Configure Certificates Profile
The Certificates Profiles allow administrators to efficiently upload corporate certificates and other essential certificates. These certificates play a crucial role in authenticating device access to the network, ensuring secure and seamless connectivity. Administrators can seamlessly manage and distribute certificates to enrolled devices from a centralized platform.
- Supported OS Version: iOS 4.0 and iPadOS 4.0 or later
- Supported Enrollment Types:
- Device Enrollment and Automated Device Enrollment
- User Enrollment
- Shared iPad Enrollment
To configure Certificate remotely on an enrolled device, follow these steps:
Navigate to SureMDM Web Console > Profiles > iOS/iPadOS > Add > Select Enrollment Type > Identity & Access Management > Certificate Management > Configure.
Enter a Profile Name and click Add.
In the Certificates prompt popup, provide the below information and click Add.
| Settings | Description |
|---|---|
| Retrieve certificate from CA server | Retrieve the certificate from a configured Certificate Authority (CA) server. |
| Certificate | Use this option to upload the certificate from the local drive. |
| Password | Specify the password for the uploaded certificate if required. |
| Certificate Name | Specify a name to identify the certificate within the profile. This name is used only for administrative reference in the SureMDM Console. Applicable only if Retrieve certificate from CA server is enabled. |
| Private Key Extractable | If enabled, the installed private key is marked as extractable on the device. Else, the private key is stored as non-extractable in the system keychain. Applicable on macOS 10.10 and later. Applicable only if Retrieve certificate from CA server is enabled. |
| Allow All Apps Access | If enabled, applications on the device are allowed to access the installed private key. Applicable on macOS 10.10 and later. Applicable only if Retrieve certificate from CA server is enabled. |
| Override Account-wide Certificate Management settings | Enable this option to override account-wide settings. Applicable only if Retrieve certificate from CA server is enabled. |
| Certificate Management Method | Select the certificate management method to use for issuing or deploying certificates to devices. Applicable only if Retrieve certificate from CA server is enabled. |
| Connection Type | Select how SureMDM connects to the Certificate Authority (CA) server for certificate management. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP. |
| CA Server Address | Specify the URL or hostname of the Certificate Authority (CA) server used to issue certificates. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP / DCOM. |
| Certificate Template | Specify the certificate template configured on the Certificate Authority (CA) server to define the properties of the issued certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP / DCOM. |
| Auto-renew before expiry (duration) | Select the number of days before expiry to automatically renew the certificate and avoid interruptions. Applicable only if Retrieve certificate from CA server is enabled. |
| Common Name Wildcard | Placeholder for the Common Name (CN) in certificates.Applicable only if Retrieve certificate from CA server is enabled. |
| Subject Alternate Name Wildcard | Placeholder for the Subject Alternative Name (SAN) in certificates. Applicable only if Retrieve certificate from CA server is enabled. |
| Challenge Type | Select the authentication method used to validate certificate enrollment requests with the Certificate Authority (CA) server. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as SCEP. |
| Username | Enter the username. Applicable only if Retrieve certificate from CA server is enabled. |
| Password | Enter the password. Applicable only if Retrieve certificate from CA server is enabled. |
| Enrollment Certificate | Upload the enrollment certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as DCOM. |
| Password | Enter the password for the enrollment certificate. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as DCOM. |
| Username | The username used for authenticating API requests to SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM). |
| Password | The password used to authenticate API requests to SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM). |
| Customer URI | Your Customer URI can be found at the end of your SCM login URL. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM). |
| Organization ID | The unique identifier assigned to your organization by SCM. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM). |
| Certificate Profile | Select the certificate profile linked to your SCM account, defining the certificate type issued. Applicable only if Retrieve certificate from CA server is enabled & Certificate Management Method is selected as Sectigo Certificate Manager(SCM). |
The added configuration will reflect in the table section.
Click Save.
The newly created profile will be listed in the Profiles section.
Go back to the Home tab and select the iOS/iPadOS device(s) or group(s).
Click Apply to launch the Apply Job/Profile To Device prompt.
In the Apply Job/Profile To Device prompt, select the created profile and click Apply.