# Certificate Certificate policy lets you deploy server CA certificates, to secure and configure features such as, Wi-Fi, E-mail etc., on managed devices. This policy is ideally used to **secure and validate network communications** from the device to any internal or external website. By pushing certificates to devices, you can secure access to networks, servers, secure e-mail communications etc. For example, you can deploy CA certificates to the managed devices if your organization uses S/MIME to connect to a network/server. The certificates pushed to the device ensures that the devices trusts the enterprise CA. **This is applicable only for Non-Samsung devices (5.0 or later), devices must be enrolled as** [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner) **or** [Profile Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner) **and for Samsung devices (above 4.2).** The managed device must have a passcode set, for Certificate to be installed in the device. ## Profile Description | Profile Specification | Description | |---|---| | Certificate File | The file to be pushed to the managed devices | | Password | This optional parameter must be entered if the certificate is password protected | 1. The certificates are added only if the certificate files are not corrupt and the correct password is provided in case of password-protected certificates. 2. On certificate expiry, upload the renewed certificate as a new certificate in the profile and then push it to the managed devices.