Configuring DigiCert PKI Platform 8 as a Certificate Authority in Jamf Pro - Technical Paper: Integrating with DigiCert Using Jamf Pro

Technical Paper: Integrating with DigiCert Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following steps are required by the CA so the Jamf Pro server can make certificate-authenticated requests to the CA as a registered authority (RA).

Requirements
  • A certificate profile for Jamf Pro configured in DigiCert

  • A client authentication certificate for your DigiCert PKI Platform 8 instance

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Global section, click PKI certificates .
  3. Click Configure New Certificate Authority .
  4. Select "DigiCert PKI Manager" as the PKI Provider, click Next, and proceed with the DigiCert Certificate Profiles Assistant.
  5. Copy the CSR from Jamf Pro and click Next.
  6. When prompted, navigate to the DigiCert PKI Platform 8 website (https://pki-manager.symauth.com/pki-manager/), and complete the following steps:
    1. Enter your PIN. If necessary, choose which certificate should be used for authentication.
    2. Navigate to Settings > Get an RA certificate.
    3. Paste the CSR that you copied from Jamf Pro, enter a certificate friendly name, and click Continue.
    4. Click Download to download the generated DigiCert RA certificate and click Done.
  7. Open the downloaded RA certificate file (.p7b) in any text editor, and copy the contents.
  8. In Jamf Pro, click Next.
  9. Enter the "DigiCert CA Configuration Name", paste the copied RA certificate into the RA Certificate Copied from DigiCert field, and click Next.
  10. If you want to automatically revoke certificates from computers or mobile devices, select Enable automatic certificate revocation.

    When automatic certificate revocation is enabled, certificates issued by DigiCert are queued for revocation immediately after the Wipe Computer, Wipe Device, or Unmanage Device action is taken. When computers or mobile devices fall out of the scope of the configuration profile that issues the certificate, the certificate will be queued for revocation after the computers or mobile devices acknowledge the remove profile command.

    Note:

    If automatic certificate revocation is enabled and you disable it, any certificates that have been marked for revocation will continue to be revoked after revocation is disabled.

    The Jamf Pro revocation service sends revocation requests either every 30 seconds or in batches of 100, depending on which constraint is met first. If there are less than 100 revocations, the revocation requests are sent 30 seconds after the first configuration profile is set to be removed. If there are 100 or more revocations, the first 100 revocation requests are sent immediately. Subsequent revocation requests are then immediately sent in groups of 100 or are deferred for 30 seconds if less than 100 remain.

  11. Click Done.
If the new certificate authority is configured successfully, it will be listed in the PKI Certificates table.