Onboard macOS devices with certificates using Jamf School and SCEP

In this topic, you will learn how to deploy Portnox™ Cloud certificates via Jamf School and SCEP to manage macOS devices.

This guide covers only network authentication. It assumes that you already manage your devices in Jamf School. If you plan to use user certificates, make sure that all devices enrolled in Jamf School have an assigned owner whose email address is the same as in the Portnox Cloud authentication repository used for the group. Also decide how to deploy the profile to your devices, for example, scope the profile to a device group so that Jamf School installs the profile automatically on each device in the group at the next device check-in.

Note:
If you want to use your own CA instead of the one provided by Portnox, you must either use your own SCEP server to generate supplicant certificates based on your CA, or have your devices obtain certificates in another way. If you use your own SCEP server with your CA, you can follow this topic, but use your own SCEP server URL instead of the Portnox SCEP server URL, and use your own CA certificate instead of the tenant CA certificate. You must also upload your CA certificate in the same section where you can download the Portnox tenant CA certificate. In the configuration profiles, you must still use the same root CA – the CA for the Portnox RADIUS server – because your devices will still use Portnox Cloud RADIUS and must be able to verify its authenticity.

Observed potential issues:

  • If Portnox Cloud shows email as the user in the certificate instead of the user’s email address, and authentication fails, check that the device has an owner in Jamf School, in the same location as the device. Without an owner, Jamf School sends variables such as %Email% as literal text.

  • Jamf School doesn’t renew SCEP certificates automatically, and Portnox Cloud doesn’t track their validity. When a certificate expires, the device loses network access. macOS devices can display a warning before the certificate expires, so users can remind you, but iOS devices don’t display any warnings. You need to manually track expiration dates and renew certificates before they expire.

    To renew a certificate, reinstall the profile on the device page, or edit and save the profile to send it again to all devices in scope.

Turn on the Portnox Cloud SCEP services

In this section, you will configure Portnox™ Cloud to provide SCEP services to your devices.

If you have previously turned on the Portnox Cloud SCEP services, skip to the later step in which you get the Cloud SCEP URL and password.

Portnox Cloud SCEP services let devices contact the Cloud SCEP server and get a unique certificate for the device or for the specific user of the device.

Important:
This topic shows the configuration for macOS computers with macOS 12 (Monterey), but the Apple profile payloads Certificate, SCEP, and WiFi, which are used in this configuration, are compatible with the following Apple operating systems: iOS 4.0+, iPadOS 4.0+, macOS 10.7+, tvOS 9.0+, watchOS 3.2+. This means that you can use the same profiles to configure other Apple devices based on these operating systems, for example, iPhones.
  1. In the Cloud portal top menu, click on the Settings option.

  2. In the Cloud portal left-hand side menu, click on the Services > GENERAL SETTINGS > SCEP Services option.

  3. Enable integration with SCEP services.

    1. Click on the Edit link.
    2. Activate the Enable integration checkbox.
    3. Click on the Save button.
  4. Click on the  ⧉  icon next to the SCEP URL field to copy the SCEP URL, and paste it in a text file for later use.
  5. Click on the  ⧉  icon next to the Password field to copy the SCEP password, and paste it in a text file for later use.

Download the root CA certificate

In this section, you will download the root CA certificate from Portnox™ Cloud, which is needed to create a profile.

  1. In the Cloud portal top menu, click on the Settings option.

  2. In the Cloud portal left-hand side menu, click on the Services > CLOUD RADIUS SERVICE > Cloud RADIUS instance option.

  3. Click on any of the RADIUS servers listed in the right-hand pane to show its configuration.

  4. Click on the Download root certificate link.

Result: The root CA certificate file is in the Downloads folder on the local disk.

Optional: Hand over information from the Portnox Cloud team to the Jamf School team

In this section, you will learn what information was collected in previous steps from Portnox Cloud, which is needed to configure Jamf School to work with Portnox Cloud.

If different people are responsible for managing Portnox Cloud and Jamf School, here is the information you need to hand over:

  • The URL of the Portnox Cloud SCEP server. For example, https://scep.portnox.com/b2973887-1274-45d4-91d0-4a342a861c76.

  • The password for the SCEP server.

  • The root CA certificate file in the X.509 format. For example, rootCertificate.crt.

Create a Jamf School profile

In this section, you will create a profile in Jamf School that lets managed devices get certificates from the Portnox™ Cloud SCEP server.

  1. Open your Jamf School instance in the browser and log in.
    For example, vorlon.jamfcloud.com
  2. In the left-hand menu, click on the Profiles option.

    Jamf School shows the Profiles pane.

  3. In the top-right corner of the Profiles pane, click on the Create Profile button.

  4. In the Create Profile window, select the platform and the profile type:
    Note:
    In this guide, we use the macOS platform and the User Enrollment profile type. The process is almost identical for other choices, with small differences such as profile section names or availability.
    1. In the Platform field, select the macOS or iOS option, depending on the devices that you want to manage. Then, click on the Next button.

    2. In the Enrollment type field, select the Device Enrollment or User Enrollment option, depending on how your devices are enrolled in Jamf School. Then, click on the Next button.

      This setting refers to the device enrollment method in Jamf School, not to the type of certificate. You can use user certificates or device certificates with both enrollment types.

    3. In the Profile name field, enter the name for this SCEP profile. Optionally, enter a description in the Description field. Then, click on the Next button.

      We used the name VORLON but you can use any name you like.

    4. Leave the Use time filter checkbox cleared, and click on the Finish button.

  5. In the left-hand menu of the profile pane, click on the SCEP option. Then, on the right-hand side, click on the Configure button, and configure SCEP properties for the profile:

    1. In the URL field, enter the SCEP URL that you copied earlier from Portnox Cloud.

    2. Leave the Name, Retries, Retry Delay, and Fingerprint fields at their default values.

      If devices time out when they request certificates, increase the values in the Retries and Retry Delay fields.

    3. In the Subject field, enter a string to use to generate the Subject field in the user/device certificates.

      The string can contain Jamf School variables. We recommend the following values:

      • For user certificates: CN=%Email%

      • For device certificates: CN=%Name% or CN=%SerialNumber%

      Jamf School replaces these variables with the owner’s email address (%Email%), the device name (%Name%), or the device serial number (%SerialNumber%). Portnox Cloud uses the Subject field for display purposes. To link the certificate to an account in your authentication repository, Portnox Cloud uses the SAN UPN field (NT Principal Name), configured in the next step.

      If you use device certificates, Portnox Cloud creates Portnox accounts for the devices. Use a human-readable device name in the Subject field so that you can identify the device on the Devices screen.

      For more information about Jamf School variables, click on the Learn how to use payload variables in your profiles link in the Need help? section at the top of the profile pane.

    4. In the Subject Alternative Name Type field, select the Uniform Resource Identifier option. In the Subject Alternative Name Value field, enter https://jamfdeviceid/%udid% if you manage macOS devices or https://jamfmobiledeviceid/%udid% if you manage iOS devices. In the NT Principal Name field, enter %Email% for user certificates, or leave the field empty for device certificates.

      Note:
      Portnox Cloud uses the NT Principal Name field (SAN UPN) to link the certificate to an account in your authentication repository. For user certificates, this field must contain the user’s email address or UPN as it appears in the authentication repository. If this field is empty or contains an incorrect value, Portnox Cloud creates a new Portnox account instead. To understand how Portnox Cloud matches the identity in the certificates with the authentication repository, see the following topic: Certificate identity information.
    5. For macOS devices, in the Certificate Expiration Notification Threshold (macOS only) field, enter the number of days before certificate expiration at which macOS shows a notification.

      This setting only shows a notification to the user. It doesn’t renew the certificate. Tell your users to contact IT when they see this notification. This field isn’t available for iOS devices.

    6. In the Challenge field, paste the password that you copied earlier from Portnox Cloud.

    7. In the Key Size field, select the key size that you want to use.

      In this example, we used the value 2048. Higher values provide more security. Values other than 1024 may cause certificate fragmentation problems in some network topologies. If such problems occur, see the following topic: Certificate fragmentation issues.

    8. In the Key usage options field, activate the Use as digital signature and Use for key encipherment checkboxes.

    9. Optional: For macOS devices, in the Options field, activate the Allow access to all apps (macOS only) checkbox.

      Network authentication works without this option. Activate it only if other apps on the device must use the certificate. Otherwise, macOS asks for the administrator’s user name and password when such an app accesses the certificate. This field isn’t available for iOS devices.

  6. In the left-hand menu of the profile pane, click on the Certificates option. Then, in the Upload new certificate section, click on the Choose File button, select the root CA certificate file that you downloaded earlier, for example, rootCertificate.crt, and click on the Upload certificate button.

    Leave the Password field empty and the Options checkboxes cleared. They apply only to PKCS#12 certificates.

  7. Click on the Save button in the bottom-right corner to save the profile.

Configure the profile for Wi-Fi

In this section, you will edit the profile and add a Wi-Fi network configuration. This will let your managed devices access the Wi-Fi network configured in Portnox™ Cloud by using certificates obtained from the Portnox SCEP server.

  1. In the left-hand menu, click on the Profiles option.

    Jamf School shows the Profiles pane.

  2. Find the profile that you created earlier, and click on the  ✎  icon in its row.

  3. In the left-hand menu of the profile pane, click on the Networks option for macOS devices or the Wi-Fi option for iOS devices. Then, on the right-hand side, click on the Configure button, and configure the network properties:

    1. In the Network Interface field, select the Wi-Fi option.

      On iOS, this field only has one option available, because iOS supports only Wi-Fi networks.

    2. In the Network SSID field, enter the SSID of the Wi-Fi network that you configured in Portnox Cloud for your managed devices.

    3. In the MAC Randomization field, activate the Disable MAC Address Randomization checkbox.

      Important:
      If you do not turn off MAC address randomization, and the supplicant certificates are not issued by Portnox SCEP, and the certificate’s SAN field does not include a Jamf or Intune device ID, Portnox Cloud assigns a new license to the device each time it connects with a different MAC address. This can significantly increase your licensing costs. Even if you use Portnox SCEP and this issue does not apply, we still recommend turning MAC address randomization off for safety. For more information, see the following topic: MAC address randomization – why it causes problems and how to turn it off.
    4. In the Security field, select the WPA2 Enterprise option.

      Note:
      You can also select another option in the Enterprise group, for example, Automatic Enterprise or WPA / WPA2 Enterprise, if it better suits your network.
    5. In the Protocols tab, in the Supported types field, activate only the TLS checkbox.

    6. In the Identity certificate field, select the SCEP option with your Portnox Cloud SCEP URL.

    7. Click on the Trust tab. Then, in the Trusted certificates field, activate the checkbox next to the root CA certificate that you uploaded earlier.

    8. Click on the + button below the Trusted servers field, and add the following name: clear-rad.portnox.com.

      Note:
      To learn more about this option, see the following topic: Trusted certificate server names.
    9. Configure the remaining settings as needed for your environment, or leave them at their default values.
  4. In the left-hand menu of the profile pane, click on the Scope option, and select the devices or device groups for this profile.
  5. Click on the Save button in the bottom-right corner to save the profile.

Configure the profile for Ethernet

In this section, you will edit the profile and add an Ethernet network configuration. This will let your managed macOS devices access the Ethernet network configured in Portnox™ Cloud by using certificates obtained from the Portnox SCEP server.

Note:
Ethernet configuration is available only for macOS devices.
  1. In the left-hand menu, click on the Profiles option.

    Jamf School shows the Profiles pane.

  2. Find the profile that you created earlier, and click on the  ✎  icon in its row.

  3. In the left-hand menu of the profile pane, click on the Networks option. Then, on the right-hand side, click on the Configure button, and configure the network properties:
    1. In the Network Interface field, select the Any Ethernet interface option.

      Note:
      You can also select another option in the 802.1x Active Ethernet or 802.1x Ethernet group, for example, First Active Ethernet interface, if it better suits your environment.
    2. In the Protocols tab, in the Supported types field, activate only the TLS checkbox.

    3. In the Identity certificate field, select the SCEP option with your Portnox Cloud SCEP URL.

    4. Click on the Trust tab. Then, in the Trusted certificates field, activate the checkbox next to the root CA certificate that you uploaded earlier.

    5. Click on the + button below the Trusted servers field, and add the following name: clear-rad.portnox.com.

      Note:
      To learn more about this option, see the following topic: Trusted certificate server names.
    6. Configure the remaining settings as needed for your environment, or leave them at their default values.
  4. In the left-hand menu of the profile pane, click on the Scope option, and select the devices or device groups for this profile.
  5. Click on the Save button in the bottom-right corner to save the profile.