- Double-click the downloaded certificate to install it in your login keychain.
- In Keychain Access, double-click the certificate and inspect its trust settings:
- If the certificate displays the message "This certificate is valid", it is successfully installed and is ready to be used for signing.Note:
If the computer the certificate is installed on is managed by the same Jamf Pro instance that created the certificate, trust should automatically be established.
- If the certificate displays the message "[Certificate Name] certificate is not trusted", it is successfully installed but not trusted.
- Do the following to establish trust so the certificate can be used for signing:
- In Jamf Pro, navigate to Settings > PKI Certificates.
- In the Management Certificate Template pane, click Download CA Certificate.
- Double-click the certificate to install it to your System keychain.
- In Keychain Access, select and double-click the certificate to view its trust settings.
- Expand the Trust disclosure triangle if needed.
- Choose "Always Trust" from the When using this certificate pop-up menu:
- When prompted, enter your administrator credentials to modify the trust settings.
- Repeat step 2 to verify the certificate that you created is valid.