Distributing DigiCert PKI Platform 8 Certificates to Devices Using the SCEP Payload - Technical Paper: Integrating with DigiCert Using Jamf Pro

Technical Paper: Integrating with DigiCert Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

After DigiCert has been added as a CA in Jamf Pro and communication between Jamf Pro and DigiCert has been established, you can distribute a certificate with DigiCert as the CA using configuration profiles in Jamf Pro. A configuration profile allows you to define settings that allow computers and mobile devices to install the CA certificate as well as allow users to access resources such as VPN or Wi-Fi.

When certificates are distributed using the SCEP payload, traffic goes directly to DigiCert PKI Platform. Traffic does not proxy through Jamf Pro. This enables both dynamic challenges and automatic revocation to harden your certificate security in SCEP workflows.

Requirements

Ensure the requirements for distributing configuration profiles are met by reviewing the requirements in the following sections of the Jamf Pro Documentation:

  1. In Jamf Pro, click Computers or Devices in the sidebar.
  2. Click Configuration Profiles in the sidebar.
  3. Click New .
  4. Use the General payload to configure basic settings, including the level at which to apply the profile and the distribution method. Only payloads and settings that apply to the selected level are displayed for the profile.
  5. To enable devices to communicate directly with the SCEP server to obtain the CA certificate, select the SCEP payload, click Configure, and do the following:
    1. Enter the provided SCEP enrollment URL from the DigiCert Certificate Profile.
    2. Enter the name of the certificate authority that appears on the DigiCert Configuration Profile in the Name field.
    3. (Optional) Select the number of days prior to certificate expiration that you want to automatically redistribute the configuration profile from the Redistribute Profile pop-up menu.
      Note:

      Configuring this option adds "$PROFILE_IDENTIFIER" to the Subject field, which is limited to 64 characters by the x.509 cryptography standard. If the Subject field exceeds 64 characters, certificates will fail to renew. For example, the profile identifier may be up to 36 characters, and if you also use a payload variable such as $USERNAME or $EMAIL with around 29 characters, you will exceed the 64-character limit.

    4. Choose "Dynamic-"DigiCert from the Challenge Type pop-up menu and select the DigiCert PKI instance you want to use.
    5. Choose the Certificate Profile ID and the Seat ID you want to use for the SCEP challenge.
      Note:

      The OIDs listed in the Configuration Profile setup page in Jamf Pro relate to the OIDs of the Certificate Profile records in the DigiCert PKI Manager. You can compare the OIDs to help ensure the Configuration Profile settings are valid and align with settings defined in the Certificate Profile record within the DigiCert PKI Manager.

      The combination of a Certificate Profile ID and Seat ID can only be used once for each configuration profile.

      You should use a Certificate Profile ID only once for each configuration profile. Reusing a Certificate Profile ID for multiple configuration profiles of the same device type can cause certificates to be incorrectly assigned. However, you can reuse the same Certificate Profile ID for configuration profiles of different device types (e.g., one computer configuration profile and one mobile device configuration profile).

      Jamf recommends that the Seat ID used for SCEP profiles be the same as the CN used in the Subject field.

      Depending on the requirements of the Certificate Profile being used in DigiCert, you may be required to configure additional settings (e.g., Key Size, Use a digital signature, and Use for key encipherment).

  6. Configure additional payloads for the profile to allow users to access resources such as VPN or Wi-Fi. Depending on how you enable devices to install the CA certificate, you may need to add the certificate to the additional payload as a trusted certificate.
  7. Click the Scope tab and configure the scope of the profile. If your PKI has been configured to automatically revoke certificates, you must configure the scope of the profile to ensure the certificates are automatically revoked from devices that fall out of the scope. For more information, see Revoking DigiCert Certificates.
  8. Click Save and select Distribute to All if you want to issue DigiCert certificates to all devices.
    Important:

    Inventory information for a user must be complete to properly issue a DigiCert certificate to a device. If there is incomplete data in inventory information for a user in Jamf Pro, DigiCert certificates will be issued with "N/A" recorded for the missing attributes.

  9. Repeat the process for all configuration profiles configured in Jamf Pro to issue DigiCert Managed PKI services certificates to computers or mobile devices.