I have an AD Certificate payload added to a configuration profile which is working well. The scoped machine obtains a certificate from the CA as expected. The problem I am seeing is that if I make a change to the profile (like the name or description), Save, and then select Distribute to All. All the machines scoped to the profile will go to the CA and obtain a another certificate. Every time I click Distribute to All, the machines grab another certificate.
Has anyone else seen this behavior? I am using 10.9.2. The CA is a Windows CA Server.
