The device certificate in the JAMF.keychain on Mac computers expires after five years. The device certificate is stored in the /Library/Application Support/JAMF/JAMF.keychain file. It is generated by Jamf Pro's built-in certificate authority and is also referenced in the PKI Certificates settings of Jamf Pro.
If the device certificate does not exist, is corrupted, does not have correct permissions, or does not match the certificate entry in the PKI Settings area of Jamf Pro, the following error message will be displayed provided that certificate-based authentication is enabled in Jamf Pro (): "Device Signature Error - A valid device signature is required to perform the action."