Components Installed for Inbound Communication Mode

Technical Paper: Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
Jamf AD CS Connector
ft:locale
en-US

Applications

When you install the inbound connector, Microsoft Internet Information Services (IIS) for Windows Server is automatically installed. Microsoft IIS is the web application server that runs the Jamf AD CS Connector. A directory named AD CS Proxy is installed in the following location:

C:\inetpub\wwwroot\adcsproxy

For more information about IIS, see the following webpage:

https://www.iis.net

In addition, the following are automatically configured when you install the inbound connector:
IIS Client Certificate Mapping Authentication
IIS is automatically configured to enable communication between Jamf Pro and the Jamf AD CS Connector to take place using IIS Client Certificate Mapping Authentication. For more information, see IIS Client Certificate Mapping Authentication <iisClientCertificateMappingAuthentication> in Microsoft's documentation.
ASP.NET
ASP.NET provides the application framework for the Jamf AD CS Connector and is integrated with the instance of the IIS web application.

Jamf AD CS Connector Certificates

When you install the Jamf AD CS Connector in inbound communication mode, the following certificates are automatically generated by the installer:
Server certificate (.pem or .cer)

The server certificate ensures trust between Jamf Pro and the Jamf AD CS Connector. It is a self-signed certificate, generated when the connector is installed.

The server certificate is exported to the current working directory with the following filename:

adcs-proxy-ca.cer

Note:

The server certificate is required when configuring Jamf Pro to communicate with the connector.

Client certificate (.pfx or .p12)

The client certificate allows Jamf Pro to authenticate with the Jamf AD CS Connector. The client certificate, generated when the connector is installed, is signed by the server certificate. It is exported in PFX format using a randomly generated password that is output to the shell during onnector installation.

Note:

The client certificate and the randomly generated password are required when configuring Jamf Pro to communicate with the Jamf AD CS Connector.