---
title: "Deploy the Root and Issuing Certificates"
slug: "mac-deploy-root-certs"
updated: 2024-12-13T19:33:12Z
published: 2024-12-13T19:33:12Z
canonical: "docs.axiad.com/mac-deploy-root-certs"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.axiad.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy the Root and Issuing Certificates

Once you've added your device to Axiad Conductor, you can start using it to enable a passwordless experience across your ecosystem.

The deployment of the certificate chain (Root and Issuing) can be done automatically and remotely using Jamf PRO.

**Prerequisites:**

1. The macOS Workstation must be already enrolled with Jamf Pro for management (see Ref5)
2. Axiad Conductor Root and Issuing certificates delivered by Axiad Professional Services in PEM (base64) format

**To Deploy the Certificate Chain**

1. In Jamf PRO, navigate to **Computers > Configuration Profiles**. ![1config-ext-external-app](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/1config-ext-external-app.png)
2. Click **New** to create a new configuration profile.
3. Enter a **Name** and **Description**, and select the **Distribution Method**.  
![cert2-name-description-dist](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert2-name-description-dist.png)
4. From the list of available configuration profiles, click **Certificate,** then click **Configure**:  
![cert3-configure](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert3-configure.png)
5. Enter a name for the certificate and select **Upload** from the **Select Certificate Options** drop-down.  
![cert4-assign-name](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert4-assign-name.png)
6. Click **Upload Certificate**.  
![cert5-upload-cert-button](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert5-upload-cert-button.png)
7. Navigate to the PEM certificate file.
8. Click **Save**.  
![cert6-save-cert-upload](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert6-save-cert-upload.png)
9. Click + on the top-right of the page.  
![cert7-add-cert-upload](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert7-add-cert-upload.png)
10. Repeat steps 3 through 6 for the Issuing certificate from Axiad Conductor.
11. Navigate to the Issuing certificate from Axiad Conductor.
12. Click **Save**.
13. When done uploading all certificates, click **Scope**.  
![cert8-scope](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert8-scope.png)
14. Click **Add** to add a target.![cert8-scope-add](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert8-scope-add.png)
15. Click **Add** next to all of the target groups of computers you to provision.  
![cert9-add-targets](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert9-add-targets.png)
16. Once you'e added all target groups, click **Done**.  
![cert9-done-targets](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert9-done-targets.png)
17. Click **Save**.  
![cert9-final](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/cert9-final.png)The new configuration profile saves.

1. Download the Root CA certificate to your Mac in PEM (base64) format.
2. Obtain your Axiad Conductor Root and Issuing certificates from your system administrator.
3. On your computer, navigate to **Finder > Applications > Utilities**.
4. Click **Keychain Access**.
5. On the left menu, in the **Keychains** section, select **System**.
6. On the left menu, in the **Category** section, select **Certificates**.
7. Click **File > Import Items**.
8. Navigate to the certificate you want to import and click **Open**.  
The certificate imports, but is not yet trusted.
9. Right-click the newly-imported certificate and select **Get Info**.
10. Expand the Trust section.
11. Next to **When using this certificate**, select **Always Trust**.  
All options automatically change to **Always Trust**.
12. Close the **Get Info** dialog box.
13. If prompted, enter your machine credentials and click **Update Settings**.  
The certificate is imported and trusted on the machine.
