Skip to main content

Configure Certificates Profile

The Certificates Profiles allow administrators to efficiently upload corporate certificates and other essential certificates. These certificates play a crucial role in authenticating device access to the network, ensuring secure and seamless connectivity. Administrators can seamlessly manage and distribute certificates to enrolled devices from a centralized platform. 

note
  • Supported OS Version: iOS 4.0 and iPadOS 4.0 or later
  • Supported Enrollment Types:
    • Device Enrollment and Automated Device Enrollment
    • User Enrollment
    • Shared iPad Enrollment

To configure Certificate remotely on an enrolled device, follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > iOS/iPadOS > Add > Select Enrollment Type > Identity & Access Management > Certificate Management > Configure.

  2. Enter a Profile Name and click Add.

  3. In the Certificates prompt popup, provide the below information and click Add.

SettingsDescription
Retrieve certificate from CA serverRetrieve the certificate from a configured Certificate Authority (CA) server.
CertificateUse this option to upload the certificate from the local drive.
PasswordSpecify the password for the uploaded certificate if required.
Certificate NameSpecify a name to identify the certificate within the profile. This name is used only for administrative reference in the SureMDM Console. Applicable only if Retrieve certificate from CA server is enabled.
Private Key ExtractableIf enabled, the installed private key is marked as extractable on the device. Else, the private key is stored as non-extractable in the system keychain. Applicable on macOS 10.10 and later. Applicable only if Retrieve certificate from CA server is enabled.
Allow All Apps AccessIf enabled, applications on the device are allowed to access the installed private key. Applicable on macOS 10.10 and later. Applicable only if Retrieve certificate from CA server is enabled.
Override Account-wide Certificate Management settingsEnable this option to override account-wide settings. Applicable only if Retrieve certificate from CA server is enabled.
Certificate Management MethodSelect the certificate management method to use for issuing or deploying certificates to devices. Applicable only if Retrieve certificate from CA server is enabled.
Connection TypeSelect how SureMDM connects to the Certificate Authority (CA) server for certificate management. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP.
CA Server AddressSpecify the URL or hostname of the Certificate Authority (CA) server used to issue certificates. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP / DCOM.
Certificate TemplateSpecify the certificate template configured on the Certificate Authority (CA) server to define the properties of the issued certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP / DCOM.
Auto-renew before expiry (duration)Select the number of days before expiry to automatically renew the certificate and avoid interruptions. Applicable only if Retrieve certificate from CA server is enabled.
Common Name WildcardPlaceholder for the Common Name (CN) in certificates.Applicable only if Retrieve certificate from CA server is enabled.
Subject Alternate Name WildcardPlaceholder for the Subject Alternative Name (SAN) in certificates. Applicable only if Retrieve certificate from CA server is enabled.
Challenge TypeSelect the authentication method used to validate certificate enrollment requests with the Certificate Authority (CA) server. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP.
UsernameEnter the username. Applicable only if Retrieve certificate from CA server is enabled.
PasswordEnter the password. Applicable only if Retrieve certificate from CA server is enabled.
Enrollment CertificateUpload the enrollment certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as DCOM.
PasswordEnter the password for the enrollment certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as DCOM.
UsernameThe username used for authenticating API requests to SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM).
PasswordThe password used to authenticate API requests to SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM).
Customer URIYour Customer URI can be found at the end of your SCM login URL. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM).
Organization IDThe unique identifier assigned to your organization by SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM).
Certificate ProfileSelect the certificate profile linked to your SCM account, defining the certificate type issued. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM).

The added configuration will reflect in the table section.

  1. Click Save.

    The newly created profile will be listed in the Profiles section.

  2. Go back to the Home tab and select the iOS/iPadOS device(s) or group(s).

  3. Click Apply to launch the Apply Job/Profile To Device prompt.

  4. In the Apply Job/Profile To Device prompt, select the created profile and click Apply.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.