Configuring DigiCert ONE as a Certificate Authority in Jamf Pro - Technical Paper: Integrating with DigiCert Using Jamf Pro

Technical Paper: Integrating with DigiCert Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following steps are required so the Jamf Pro server can make certificate-authenticated requests to the CA as a registered authority (RA).

Requirements
  • Jamf Pro 11.17.0 or later

  • A client authentication certificate for your DigiCert instance

  • Enough seats available in DigiCert for all target devices

    Note:

    DigiCert certificates are issued multiple times to computers during profile re-enrollment. If deleting an MDM profile from a computer or removing it by executing the command, sudo jamf removeFramework, active DigiCert certificates will be issued multiple times during profile re-enrollment.

  • A certificate profile for Jamf Pro configured in DigiCert ONE Trust Lifecycle Manager

    • If you are planning to deploy certificates using the SCEP payload, set the enrollment method of the certificate profile in DigiCert Trust Lifecycle Manager to "SCEP".
      Note:You must pre-load seats in DigiCert Trust Lifecycle Manager to ensure you can successfully issue certificates to computers or mobile devices from Jamf Pro. Jamf Pro can automatically create seat records when configuring a SCEP certificate payload, or you can manually create seats via bulk-upload of a CSV within DigiCert Trust Lifecycle Manager, or via the DigiCert Trust Lifecycle Manager REST API. For more information, see Create seats in bulk and enroll against your profile or DigiCert Trust Lifecycle Manager REST API from DigiCert.
    • If you are planning to deploy certificates using the Certificate payload, set the enrollment method to "REST API" and the authentication method to "3rd Party App".
      Important:

      When using the certificate payload, the "Key sizes" must be limited to RSA 2048. RSA 4096 is not supported.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Global section, click PKI certificates .
  3. Click Configure New Certificate Authority.
  4. Select DigiCert ONE Trust Lifecycle Manager.
  5. Enter a display name in the Display Name for the Integration field.
  6. (Optional) If you want to automatically revoke certificates from computers or mobile devices, select Enable automatic certificate revocation.

    When automatic certificate revocation is enabled, certificates issued by DigiCert are queued for revocation immediately after the Wipe Computer, Wipe Device, or Unmanage Device action is taken. When computers or mobile devices fall out of the scope of the configuration profile that issues the certificate, the certificate is queued for revocation after the computers or mobile devices acknowledge the remove profile command.

    Note:

    If automatic certificate revocation is enabled and you disable it, any certificates that have been marked for revocation will still be revoked after revocation is disabled.

  7. Upload the client authentication certificate for your DigiCert instance.
  8. Enter the password for the certificate in the Certificate password field.
  9. Click Save.
A banner displays in the Jamf Pro interface confirming communication has been successfully established between DigiCert and Jamf Pro. The new certificate authority is listed in the PKI Certificates table.