Active Directory Certificate
com.apple.ADCertificate.managed
The payload that configures Active Directory Certificate settings.
Configuration Keys (13)
| Key | Type | Title |
|---|---|---|
DescriptionrequiredA user-friendly description of the certification identity. | string | Description |
CertServerrequiredThe fully qualified host name of the CA. | string | Certificate server |
CertificateAuthorityrequiredmacOS 10.8+ The name of the certificate authority (CA), which the device determines from the common name (CN) of the Active Directory entry. Valid values: CN=<your CA Name> CN='Certification Authorities' CN='Public Key Services' CN='Services' CN='Configuration' CN=<your base Domain Name> | string | Certificate authority |
CertTemplaterequiredThe certificate template for your environment. The default user certificate value is 'User'. The default computer certificate value is 'Machine'. Default: "User" | string | Certificate template |
CertificateAcquisitionMechanismmacOS 10.8+ This value is most commonly 'RPC'; if using web enrollment, use 'HTTP'. Range: RPC, HTTP | string | Certificate acquisition mechanism |
CertificateRenewalTimeIntervalrequiredThe number of days in advance of certificate expiration that the notification center notifies the user. Default: 14 | integer | Certificate renewal time interval |
KeysizerequiredmacOS 10.11+ The RSA key size for the certificate signing request (CSR). Default: 2048 | integer | Key size |
PromptForCredentialsmacOS 10.8+ If 'true', the system prompts the user for credentials when is installs the profile. This key applies only to user certificates with the Manual Download profile delivery method. Omit this key for computer certificates. Default: false | boolean | Prompt for credentials |
UserNameThe user name with which to authenticate to the certificate server | string | User name |
PasswordThe password with which to authenticate to the certificate server | string | Password |
AllowAllAppsAccessmacOS 10.10+ If 'true', gives apps access to the private key. Default: false | boolean | Allow all apps access |
KeyIsExtractablemacOS 10.10+ If 'true', the system allows exporting the private key. Default: false | boolean | Key is extractable |
EnableAutoRenewalmacOS 10.13.4+ If 'true', the certificate obtained with this payload attempts auto-renewal. Auto-renewal can only be used with device Active Directory certificate payloads. Default: false | boolean | Enable auto renewal |