Skip to main content

Sectigo Certificate Management

Overview

Sectigo Certificate Management in SureMDM enables administrators to integrate the platform with Sectigo Certificate Manager (SCM) for centralized device certificate management. This integration automates certificate provisioning, renewal, and revocation, ensuring secure device authentication and communication while minimizing manual administrative effort.

Prerequisite

Before configuring Sectigo Certificate Management in SureMDM, ensure you have access to the Sectigo portal and the SureMDM console.

Retrieve Required Values from the Sectigo Portal

To retrieve these values, log in to the Sectigo portal and follow the steps below:

  1. Username and Password

    Username: Log in to the Sectigo portal, click My Profile, and note the displayed username.

    Password: Use the password associated with your Sectigo portal login.

    alt text

    alt text

  2. Customer URI

    Retrieve the Customer URI from the Sectigo portal login page URL. Copy the Customer URI portion from the login URL.

    alt text

  3. Organization ID

    The Organization ID is available in the Sectigo portal. To find it, navigate to Menu > Organizations and note the displayed Organization ID.

    alt text

Configuration of Sectigo Certificate Management in SureMDM

Once the required values (Username, Password, Customer URI, and Organization ID) are retrieved from the Sectigo portal, follow these steps to configure Sectigo Certificate Management in SureMDM:

  1. Log in to SureMDM Console.

  2. Navigate to Account Settings > Certificate Management.

  3. Configure the following settings:

SettingsDescription
Certificate Management MethodSelect Sectigo
CA Server AddressSectigo SCEP URL (Refer to e.iii under SCEP configurations sectigo Configurations.)
User Name and PasswordEnter the user name and password
Customer URIEnter the Customer URI
Organization IDEnter the Organization ID
Certificate Renewal PeriodSelect the Renewal period
Certificate ProfileSelect the Certificate Profile from the drop-down.
Common Name Wild CardSelect wildcards from the drop-down, such as IMEI, Mac Address, Device ID, Serial number, or Custom wildcards/values. Custom wildcards can be E = %emailaddress% ,CN = %cn% , %ou% , %dc%
Subject Alternate Name WildcardSelect wildcards such as IMEI, Mac Address, Device ID, Serial number, or Custom wildcards/values from the drop-down. Custom wildcards can be Principal Name = %upn%, RFC822 Name= %emailaddress%

alt text

  1. Click Fetch Profiles and select any profile from the dropdown list.

alt text

  1. Select the Certificate Renewal Period, then enter the Common Name Wildcard and Subject Alternate Name Wildcard.

alt text

  1. Click Save to apply the changes.

alt text

  1. Create a Certificate Profile and deploy it to devices.

  2. Click Get Managed Certificates to renew or revoke the certificate manually.

alt text

Create a Certificate Profile in SureMDM

  1. Log in to the SureMDM Console.

  2. Navigate to Profiles > Android.

  3. Click Add Profile and enter the Profile Name.

  4. From the left pane, select Certificate.

  5. Click Add to open the Certificate configuration window

  6. Configure the certificate settings as shown:

alt text

  • Enable Retrieve certificate from CA server.
  • Select Certificate Usage (for example, VPN and Apps)
  • Enter the Certificate Name.
  • (Optional) Enable Override Account-wide Certificate Management settings, if required.
  • Enter the Package ID if the certificate is intended for a specific application.
  1. Click Add to save the certificate configuration.

alt text

  1. Click Save to save the profile. Once the profile is created, it can be applied to the required devices or device groups for certificate issuance.