Distributing DigiCert ONE Trust Lifecycle Manager Certificates to Devices Using a Configuration Profile - Technical Paper: Integrating with DigiCert Using Jamf Pro

Technical Paper: Integrating with DigiCert Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

After DigiCert has been added as a CA in Jamf Pro and communication between Jamf Pro and DigiCert has been established, you can distribute a certificate with DigiCert as the CA using configuration profiles in Jamf Pro. A configuration profile allows you to define settings that allow computers and mobile devices to install the CA certificate as well as allow users to access resources such as VPN or Wi-Fi.

Requirements

Ensure the requirements for distributing configuration profiles are met by reviewing the requirements in the following sections of the Jamf Pro Documentation:

  1. In Jamf Pro, click Computers or Devices in the sidebar.
  2. Click Configuration Profiles in the sidebar.
  3. Click New .
  4. Use the General payload to configure basic settings, including the level at which to apply the profile and the distribution method. Only payloads and settings that apply to the selected level are displayed for the profile.
  5. Do one of the following:
    • If you are distributing certificates with a SCEP payload:
      1. In the Challenge Type pop-up menu, select Dynamic-DigiCert Trust Lifecycle Manager.

      2. In the PKI Instance pop-up menu, select your DigiCert integration.

      3. In the Certificate Profile pop-up menu, select the certificate profile that you created in DigiCert.

      4. In the Seat ID pop-up menu, select the seat ID mapping that you want devices to send to DigiCert for identification.

      5. In the Seat Type pop-up menu, select the type of seat that should be automatically created in DigiCert.

        You can select "None" if you prefer to manually create seats in DigiCert instead.

      6. (Optional) Configure the remaining fields with custom settings as needed for your environment.

    • If you are distributing certificates with a Certificate payload.
      1. Enter a display name in the Certificate Name field.

      2. In the Select Certificate Option pop-up menu, select your DigiCert ONE integration.

      3. In the Certificate Profile ID pop-up menu, select the certificate profile from DigiCert that you want to deploy.

      4. In the Seat ID pop-up menu, select the seat ID mapping that you want devices to send to DigiCert for identification.

      5. Complete the Attribute Mapping settings with the information devices should send to DigiCert for identification.

      6. (Optional) Configure the remaining fields with custom settings as needed for your environment.

  6. Configure additional payloads for the configuration profile to allow users to access resources such as VPN or Wi-Fi. Depending on how you enable devices to install the CA certificate, you may need to add the certificate to an additional payload as a trusted certificate.
  7. Click the Scope tab and scope the configuration profile to the appropriate devices.
  8. Click Save and select Distribute to All if you want to issue DigiCert certificates to all devices.
    Important:

    Inventory information for a user must be complete to properly issue a DigiCert certificate to a device. Incomplete user inventory information will cause DigiCert certificates to be issued with "N/A" recorded for the missing attributes.

The configuration profile is deployed to target devices.

If you chose to distribute certificates with a SCEP payload, target devices are queued to obtain certificates. The timeframe for actual certificate deployment depends on server load (typically within 5 minutes or at the next device check-in).

If you chose to distribute certificates with the Certificate payload, Jamf Pro automatically redistributes the certificate via a new configuration profile 10 days before the certificate expires. (If the 10-day default setting does not meet your needs, contact Jamf Support.)