Apple Code Signing Certificate Selection for macOS MDM
search cancel

Apple Code Signing Certificate Selection for macOS MDM

book

Article ID: 443932

calendar_today

Updated On:

Products

Client Management Suite IT Management Suite

Issue/Introduction

Selecting the correct certificate from the Apple Developer Program ensures that MDM profiles and packages deployed to macOS endpoints are recognized as "Verified." This article identifies which certificate type to select when creating a Signing Certificate for the Symantec Management Platform (SMP).The Apple Developer program provides a code signing certificate with the membership. When the solution does not require publishing to the Apple App Store, a specific certificate selection is required to ensure profiles and other packages are trusted by macOS endpoints.

Environment

  • IT Management Suite (ITMS) 8.x
  • Client Management Suite (CMS) 8.x
  • macOS 11.0 and higher

Resolution

The Developer ID Application certificate is compatible with the product UI for signing MDM profiles and delivering them to macOS endpoints.

To ensure the certificate used for signing displays as "Verified," the endpoints must trust it. Certificates issued by well-known Certificate Authorities (CAs) are typically trusted on endpoints by default. Apple root and intermediate certificates are publicly available at the

 https://www.apple.com/certificateauthority/

 

Additional Information