Category Filter
 
 

Last updated: August 14, 2026

Certificates

This page covers the macOS Certificate Profile in MDM, explaining how administrators can deploy server CA certificates to managed devices to secure and validate network communications. It describes how pushing certificates enables secure access to internal and external networks, servers, and email including S/MIME. The Profile Description table outlines key configuration fields such as Certificate File, Password, and Private Key export options. The page also addresses certificate renewal, handling corrupt files, and supported platforms including macOS, tvOS, and iOS.

Certificate policy lets you deploy server CA certificates, to secure and configure features such as, Wi-Fi, E-mail etc., in the managed devices. This policy lets you distribute certificates to mobile devices and ideally used to secure and validate network communications from the device to any internal/external website. By pushing certificates to device, you can secure access to networks/servers, secure e-mail communication etc., For example, you can deploy CA certificates to the managed devices, if your organization uses S/MIME to connect to a network/server. The certificates pushed to the device ensures the devices trusts the enterprise CA. This payload is supported for macOS, tvOS and iOS devices.

For scaleable and and simplified distribution of certificates in large organizations, you can configure Simple Certificate Enrollment Protocol(SCEP)

Profile Description

Profile SpecificationDescription
Certificate FileThe file to be pushed to the managed devices
PasswordThis optional parameter must be entered if the certificate is password protected
Private Key export from KeychainAllows/ Restricts exporting the Private Key from the Keychain
Third Party Apps accessing the Associated Private KeyAllows/Restricts Third Party Apps to access the Private Key
  1. The certificates are added only if the certificate files are not corrupt and the correct password is provided in case of password-protected certificates.
  2. On certificate expiry, upload the renewed certificate as a new certificate in the profile and then push it to the managed devices.

FAQ

After distributing a certificate from the MDM console, how do you trust the certificate on the managed devices?
When a certificate is distributed from an MDM, it is automatically trusted by the device; no manual steps are required.

Frequently Asked Questions

After distributing a certificate from the MDM console, how do you trust the certificate on the managed devices?
When a certificate is distributed from an MDM, it is automatically trusted by the device; no manual steps are required.

What happens if I upload a corrupt certificate file?
The certificate will not be added to the profile. Ensure the file is not corrupt and, if password-protected, that the correct password is provided.

How do I renew an expired certificate?
Upload the renewed certificate as a new certificate in the profile, then push the updated profile to the managed devices.

Which device platforms support this Certificate payload?
This payload is supported for macOS, tvOS, and iOS devices.

Jump To