The following steps are required so the Jamf Pro server can make certificate-authenticated requests to the CA as a registered authority (RA).
Jamf Pro 11.17.0 or later
A client authentication certificate for your DigiCert instance
Enough seats available in DigiCert for all target devices
Note:DigiCert certificates are issued multiple times to computers during profile re-enrollment. If deleting an MDM profile from a computer or removing it by executing the command,
sudo jamf removeFramework, active DigiCert certificates will be issued multiple times during profile re-enrollment.A certificate profile for Jamf Pro configured in DigiCert ONE Trust Lifecycle Manager
- If you are planning to deploy certificates using the SCEP payload, set the enrollment method of the certificate profile in DigiCert Trust Lifecycle Manager to . Note:You must pre-load seats in DigiCert Trust Lifecycle Manager to ensure you can successfully issue certificates to computers or mobile devices from Jamf Pro. Jamf Pro can automatically create seat records when configuring a SCEP certificate payload, or you can manually create seats via bulk-upload of a CSV within DigiCert Trust Lifecycle Manager, or via the DigiCert Trust Lifecycle Manager REST API. For more information, see Create seats in bulk and enroll against your profile or DigiCert Trust Lifecycle Manager REST API from DigiCert.
- If you are planning to deploy certificates using the Certificate payload, set the enrollment method to and the authentication method to . Important:
When using the certificate payload, the must be limited to RSA 2048. RSA 4096 is not supported.
- If you are planning to deploy certificates using the SCEP payload, set the enrollment method of the certificate profile in DigiCert Trust Lifecycle Manager to .