# Certificate Last updated: August 14, 2026 This page explains how to configure and deploy the Chromebook Certificate Profile in ManageEngine MDM. Administrators can push server CA certificates to managed Chromebook devices to secure network communications, Wi-Fi, and email access. The profile supports optional password-protected certificates, and covers key scenarios such as deploying CA certificates for S/MIME connections. It also addresses certificate expiry handling and common troubleshooting questions around certificate validation and password requirements. Certificate policy lets you deploy server CA certificates, to secure and configure features such as, Wi-Fi, E-mail etc., on the managed devices. This policy is ideally used to **secure and validate network communications** from the device to any internal/external website. By pushing certificates to device, you can secure access to networks/servers, secure e-mail communication etc., For example, you can deploy CA certificates to the managed devices, if your organization uses S/MIME to connect to a network/server. The certificates pushed to the device ensures the devices trusts the enterprise CA. | Profile Specification | Description | |---|---| | Certificate File | The file to be pushed to the managed devices | | Password | This optional parameter must be entered if the certificate is password protected | 1. The certificates are added only if the certificate files are not corrupt and the correct password is provided in case of password-protected certificates. 2. On certificate expiry, upload the renewed certificate as a new certificate in the profile and then push it to the managed devices. ## Frequently Asked Questions **What happens to devices when a pushed certificate expires?** The expired certificate is not renewed automatically. You must upload the renewed certificate as a new certificate in the profile and push it to the managed devices again. **Why isn't my certificate getting added to the profile?** Certificates are added only if the certificate file is not corrupt and, for password-protected certificates, the correct password is provided. **Do I need a password to push a certificate?** A password is required only if the certificate file itself is password protected; it is an optional parameter otherwise.