Step 2: Configuring AD CS as a Certificate Authority for Inbound Communication Mode

Technical Paper: Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
Jamf AD CS Connector
ft:locale
en-US

You can configure the PKI certificates settings in Jamf Pro to use AD CS as a certificate authority.

Adding AD CS as a certificate authority in Jamf Pro requires you to configure the AD CS integration settings and the Jamf AD CS Connector settings. This involves defining the location of the connector and AD CS servers and adding client and server certificates to permit authentication between Jamf Pro and the connector.

After you add AD CS as a certificate authority in Jamf Pro, you can use the PKI certificates settings in Jamf Pro to view and edit information about the CA. In addition, you can use the PKI certificates settings to view information about the active, expired, or inactive AD CS certificates that have been distributed to devices via configuration profiles.

Requirements

The Jamf AD CS Connector must be installed in inbound communication mode. You need the connector certificates that are generated when you install the connector.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Global section, click PKI certificates .
  3. Click the Certificate Authority tab, and then click Configure New Certificate Authority.
  4. Select Active Directory Certificate Services (AD CS) and click Next.
  5. In the AD CS Server Integration area, do the following:
    1. Enter a display name for the integration in the Display Name for Integration field.
    2. Enter the name of the certificate authority in the CA Name field.

      The CA name is the common name of the issuing certification authority.

    3. Enter the fully qualified domain name of the server that hosts AD CS in the Fully Qualified Domain Name field.
  6. In the Jamf AD CS Connector area, select or deselect the Automatic certificate revocation checkbox as needed.

    When automatic certificate revocation is enabled, certificates issued by AD CS are queued for revocation immediately after the Wipe Computer, Wipe Device, or Unmanage Device action is taken. When computers or mobile devices fall out of the scope of the configuration profile that issues the certificates, the certificate will be queued for revocation after the computers or mobile devices acknowledge the remove profile command.

    Note:

    If automatic certificate revocation is enabled and you disable it, any certificates that have been marked for revocation will continue to be revoked after revocation is disabled.

    The Jamf Pro revocation service sends revocation requests either every 30 seconds or in batches of 100, depending on which constraint is met first. If there are less than 100 revocations, the revocation requests are sent 30 seconds after the first configuration profile is set to be removed. If there are 100 or more revocations, the first 100 revocation requests are sent immediately. Subsequent revocation requests are then immediately sent in groups of 100 or are deferred for 30 seconds if less than 100 remain.

  7. Click Inbound as the connector mode, and then do the following:
    1. In the Certificates area, enter the URL for the location of the Jamf AD CS Connector.
    2. Click Upload to upload the server certificate (.pem or .cer), and follow the onscreen instructions.

      This certificate is generated by the Jamf AD CS Connector installer.

    3. To upload the client certificate (.pfx or .p12), click Upload and follow the onscreen instructions.

      This certificate is generated during the Jamf AD CS Connector installation.

  8. Click Save .
  9. Click Done.

AD CS is listed as a CA on the Certificate Authorities tab.

When integration with AD CS is complete, you can use Jamf Pro to distribute certificates to devices using configuration profiles with AD CS as the certificate authority. For more information, see Distributing AD CS Certificates Using the Certificate Payload.

In addition, if your environment uses in-house apps that have been developed with the Jamf Certificate SDK, you can use Jamf Pro to distribute them. For more information, see Distributing an In-House App Developed with the Jamf Certificate SDK.