Enrolled Devices Stop Communicating after 5 Years

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

After computers and mobile devices are enrolled for five years, the following certificates expire:

  • Device identity certificateThe device identity certificate in the MDM profile expires and prevents MDM functionality from working. This can result in MDM commands in configuration profiles to not complete and remain pending.
  • Device certificateThe device certificate in the JAMF.keychain that is used for the Jamf management framework expires on computers. This can result in the following error when executing a jamf binary communication command, such as sudo jamf policy or sudo jamf recon:
    "Device Signature Error - A valid device signature is required to perform the action"

Starting with Jamf Pro 10.23.0, when devices are enrolled or renewed, the device identity certificate and device certificate will expire after two years. Jamf Pro 10.23.0 or later allows you to manually renew the MDM profile and its device identity certificate for a single device or multiple devices via a mass action. In addition, when Jamf Pro's built-in certificate authority is renewed, the device identity certificate used in the MDM profile is automatically renewed.

Starting with Jamf Pro 10.25.0, the MDM Profile Settings feature allows you to configure renewal options for the MDM Profile containing the device identity certificate on computers and mobile devices. You can choose to renew the MDM profile when the Jamf Pro's built-in certificate authority is renewed or select the number of days before the MDM profile expires to renew it. To access this feature, in Jamf Pro navigate to Settings > Global > MDM Profile Settings.

Starting with Jamf Pro 10.27.0, computer device certificates are automatically renewed 180 days before the expiration date.