Distributing DigiCert PKI Platform 8 Certificates to Devices Using the Certificate Payload - Technical Paper: Integrating with DigiCert Using Jamf Pro

Technical Paper: Integrating with DigiCert Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

After DigiCert has been added as a CA in Jamf Pro and communication between Jamf Pro and DigiCert has been established, you can distribute a certificate with DigiCert as the CA using configuration profiles in Jamf Pro. A configuration profile allows you to define settings that allow computers and mobile devices to install the CA certificate as well as allow users to access resources such as VPN or Wi-Fi.

Using configuration profiles, you can distribute the CA certificate directly to devices using the Certificate payload in Jamf Pro.
Note:

Jamf Pro automatically redistributes the certificate via a configuration profile 10 days before the certificate expires. If the 10-day default setting does not meet your needs, contact Jamf Support.

Certificates are not deployed immediately. The configuration profile is queued to obtain a certificate. Once the Certificate payload and configuration profile are complete, the configuration profile will be deployed to the device. The timeframe for certificate deployment depends on server load and typically is 5 minutes, or the next device check-in.
Note:

Jamf Pro automatically redistributes the certificate via a configuration profile 10 days before the certificate expires. If the 10-day default setting does not meet your needs, contact Jamf Support.

Requirements

Ensure the requirements for distributing configuration profiles are met by reviewing the requirements in the following sections of the Jamf Pro Documentation:

  1. In Jamf Pro, click Computers or Devices in the sidebar.
  2. Click Configuration Profiles in the sidebar.
  3. Click New .
  4. Use the General payload to configure basic settings, including the level at which to apply the profile and the distribution method. Only payloads and settings that apply to the selected level are displayed for the profile.
  5. Select the Certificate payload, click Configure, and do the following:
    1. Enter a display name and then choose a DigiCert instance from the Select Certificate Option pop-up menu.
    2. Use the settings on the pane to specify information about the CA.
  6. Configure additional payloads for the profile to allow users to access resources such as VPN or Wi-Fi. Depending on how you enable devices to install the CA certificate, you may need to add the certificate to the additional payload as a trusted certificate.
  7. Click the Scope tab and configure the scope of the profile. If your PKI has been configured to automatically revoke certificates, you must configure the scope of the profile to ensure the certificates are automatically revoked from devices that fall out of the scope. For more information, see Revoking DigiCert Certificates.
  8. Click Save and select Distribute to All if you want to issue DigiCert certificates to all devices.
    Important:

    Inventory information for a user must be complete to properly issue a DigiCert certificate to a device. If there is incomplete data in inventory information for a user in Jamf Pro, DigiCert certificates will be issued with "N/A" recorded for the missing attributes.

  9. Repeat the process for all configuration profiles configured in Jamf Pro to issue DigiCert Managed PKI services certificates to computers or mobile devices.