Hi everyone,
the first renewal of the radius cert is due in a month and I am not confident on how to do this without disconnecting all of our 250+ clients.
I believe I have perhaps made mistakes regarding best practices. However, I had no other choice since all certs and network payloads needed to be in one profile. The Jamf Profile used to deploy the 802.1x auth contains:
- the RADIUS cert
- the CA cert
- the info about which cert template to use to issue a cert for any given machine
- the wired and wireless network configuration settings with the certificates used to connect.
All certs are issued via the ADCS server to be able to renew automatically since MacOS and IOS would not be able to do this if done without it.
As far as I understood it, it had to be done this way, (all in one approach) to be able to select the cert to use for any given network connection that the conf-profile is controlling.
However, once I would re-redeploy this conf-profile, the clients would lose the connection before receiving the new config. Is it possible to deploy the renewed RADIUS certificate in a separate conf-profile? Then, however, I would not be able to select the cert in the WiFi and ethernet payload section... Any hints in the right direction are appreciated. If there is a better way to accomplish this.
with kind regards, Julian Niedzwetzki

