Distributing AD CS Certificates Using the SCEP Payload

Technical Paper: Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
Jamf AD CS Connector
ft:locale
en-US

After communication between Jamf Pro and AD CS has been established, you can use Jamf Pro to distribute certificates with AD CS as the certificate authority to computers and mobile devices in your environment using configuration profiles.

When certificates are distributed using the SCEP payload, traffic flows through Jamf Pro and then to AD CS. This enables both dynamic challenges and automatic revocation to harden your certificate security in SCEP workflows.

Requirements

Ensure the requirements for distributing configuration profiles are met by reviewing the requirements in the following sections of the Jamf Pro Documentation:

  1. In Jamf Pro, click Computers or Devices in the sidebar.
  2. Click Configuration Profiles in the sidebar.
  3. Click New .
  4. Use the General payload to configure basic settings, including the level at which to apply the profile and the distribution method. Only payloads and settings that apply to the selected level are displayed for the profile.
  5. To enable devices to communicate directly with the SCEP server to obtain the CA certificate, select the SCEP payload, and then click Configure.
  6. In the Certificate Authority Type area, select AD CS.
  7. Select the AD CS certificate authority you want to use to distribute certificates from the AD CS Certificate Authority pop-up menu.

    The pop-up menu lists the display names entered in the Display Name for Integration field in the PKI certificates settings.

  8. Enter the template name that you configured on the connector.
    Note:

    Ensure that you enter the template name and not the template display name. For more information, see Configuring a Template and Permissions on the Active Directory Certificate Services (AD CS) Server.

  9. (Optional) If you want the configuration profile to be redistributed to devices before the certificate expires, select the number of days before the expiration date that you want from the Redistribute Profile pop-up menu.
    Note:

    Configuring this option adds "$PROFILE_IDENTIFIER" to the Subject field, which is limited to 64 characters by the x.509 cryptography standard. If the Subject field exceeds 64 characters, certificates will fail to renew. For example, the profile identifier may be up to 36 characters, and if you also use a payload variable such as $USERNAME or $EMAIL with around 29 characters, you will exceed the 64-character limit.

  10. (Optional) Enter the appropriate keys and values in the Subject field.
    Note:

    If you are using the PROFILE_IDENTIFIER payload variable, it must be the first substitution in the Subject field.

  11. (Optional) Choose a Subject Alternative Name Type if needed.
    Note:

    The "Dynamic-AD CS" Challenge Type is selected by default.

  12. (Optional) If you want to retry the certificate request, enter values in the Retries and Retry Delay, and Certificate Expiration Notification Threshold fields.
  13. (Optional) Depending on the requirements of the certificate profile being used in AD CS, you may be required to configure additional settings (e.g., Key Size, Use as digital signature, Use for key encipherment and Fingerprint).
  14. Select the appropriate values for your workflow using the Allow export from keychain and Allow all apps access checkboxes.
  15. Click the Scope tab and scope the configuration profile to the appropriate devices.
  16. Click Save .