Renewing a Device Certificate

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The device certificate in the JAMF.keychain on Mac computers expires after five years. The device certificate is stored in the /Library/Application Support/JAMF/JAMF.keychain file. It is generated by Jamf Pro's built-in certificate authority and is also referenced in the PKI Certificates settings of Jamf Pro.

If the device certificate does not exist, is corrupted, does not have correct permissions, or does not match the certificate entry in the PKI Settings area of Jamf Pro, the following error message will be displayed provided that certificate-based authentication is enabled in Jamf Pro (Settings > Computer Management > Security > Enable certificate-based authentication): "Device Signature Error - A valid device signature is required to perform the action."