This article applies to Jamf Cloud-hosted environments that use a custom domain and utilize AWS Certificate Manager (ACM) email validation for annual certificate renewal.
Not available for Jamf GovCloud Premium Cloud Plus
Before the Amazon certificate authority (CA) can issue a certificate for your site, ACM must verify your ownership or control of all specified domains in your request. For administrators using email verification, ACM sends validation email messages to the system emails for each domain annually.
- Present to 15 March 2026: Maximum lifetime of 398 days
- 15 March 2026: Maximum lifetime reduces to 200 days
- 15 March 2027: Maximum lifetime reduces to 100 days
- 15 March 2029: Maximum lifetime reduces to 47 days
For more information, see TLS Certificate Lifetimes Will Officially Reduce To 47 Days from DigiCert.
If you miss an ACM validation, your devices cease communication with Jamf Pro server, which will cause failed enrollments and Self Service connections.
Jamf recommends that administrators transition to Domain Name System (DNS) validation, which requires only a one-time setup. Note the following during the transition:
- ACM provides $CNAME records for addition to your domain's DNS server.
- Records contain unique key-value pairs proving domain control.
- $CNAME records should remain in place to enable automatic certificate renewal.
If you need assistance with the DNS validation setup process, log in to Jamf Account, and click Contact Support in the top navigation.