After computers and mobile devices are enrolled for five years, the following certificates expire:
- Device identity certificate —The device identity certificate in the MDM profile expires and prevents MDM functionality from working. This can result in MDM commands in configuration profiles to not complete and remain pending.
- Device certificate —The device certificate in the JAMF.keychain that is used for the Jamf management framework expires on computers. This can result in the following error when executing a jamf binary communication command, such as
sudo jamf policyorsudo jamf recon:"Device Signature Error - A valid device signature is required to perform the action"
Starting with Jamf Pro 10.23.0, when devices are enrolled or renewed, the device identity certificate and device certificate will expire after two years. Jamf Pro 10.23.0 or later allows you to manually renew the MDM profile and its device identity certificate for a single device or multiple devices via a mass action. In addition, when Jamf Pro's built-in certificate authority is renewed, the device identity certificate used in the MDM profile is automatically renewed.
Starting with Jamf Pro 10.25.0, the MDM Profile Settings feature allows you to configure renewal options for the MDM Profile containing the device identity certificate on computers and mobile devices. You can choose to renew the MDM profile when the Jamf Pro's built-in certificate authority is renewed or select the number of days before the MDM profile expires to renew it. To access this feature, in Jamf Pro navigate to .
Starting with Jamf Pro 10.27.0, computer device certificates are automatically renewed 180 days before the expiration date.