- In Jamf Pro, click Computers or Devices in the sidebar.
- Click Configuration Profiles in the sidebar.
- Click New .
- Use the General payload to configure basic settings, including the level at which to apply the profile and the distribution method. Only payloads and settings that apply to the selected level are displayed for the profile.
- Select the SCEP payload and click Configure.
- Select Use the External Certificate Authority settings to enable Jamf Pro as SCEP proxy for this configuration profile. The PKI Certificates settings are applied to the configuration profile.Note:
You can customize the profile by modifying the Subject and Subject Alternative Name Type settings.
- Enter the name of the instance in the Name field. Note:
For Microsoft certificate authorities, SERVERNAME-MSCEP-RA is an example. If you do not enter a name, SCEP Proxy is populated by default in the Name field.
- If you are using an Entrust CA, do the following:
- Enter the name of your Digital ID Configuration that issues certificates for Entrust in the Digital ID Configuration Name field.
- Enter the iggroup variable defined in your Entrust Digital ID Configuration in the Group Name field.
- Click Add to add additional RDN variables, and then enter the variable name and value.
- Use the rest of the payloads to configure the settings you want to apply including the certificates you want to distribute with the profile.Note:
Jamf recommends that you distribute one certificate per configuration profile.
- Click the Scope tab and configure the scope of the profile.
- (Optional) If you chose to distribute the profile in Self Service, click the Self Service tab to configure Self Service settings for the profile.Note:
If your profile is configured to automatically redeploy before expiration, you must use "Install Automatically" as the primary deployment method. Self Service can still be used as a supplemental or fallback option, but will not work to redistribute profiles unless end users manually reinstall from Self Service.
- Click Save .
If you want to disable Jamf Pro as SCEP Proxy for configuration profiles in the PKI Certificates settings, you must first disable Jamf Pro as SCEP Proxy for any configuration profiles that have the option enabled.