ACME device attestation
ACME device attestation uses device identity to authenticate managed devices during certificate enrollment. A mobile device management (MDM) platform, such as Jamf, initiates certificate enrollment on behalf of managed devices. DigiCert® Trust Lifecycle Manager validates each device's attestation before issuing a certificate from a DigiCert® Private CA.
ACME device attestation currently supports Apple devices only. This enrollment method ensures that certificate private keys are generated and stored securely in the device's hardware.
How ACME device attestation works
Before certificate enrollment, configure your Trust Lifecycle Manager account. You create a certificate profile using the
CA Manager Device Attestation Certificatebase template and the 3rd-party ACME device attestation enrollment method.You must then configure your mobile device management (MDM) platform to deploy ACME enrollment profiles to managed devices.
During enrollment, Trust Lifecycle Manager validates the device's hardware-backed attestation before requesting a certificate from the issuing CA.
After enrollment, you can use Trust Lifecycle Manager to view and manage the issued certificates.