Prior to enrolling an OSX client, if I update the Tomcat certificate with one from an internal Microsoft CA, does the client need to trust the Tomcat certificate to successfully enroll and get configuration profiles? Basically I'm replacing the certificate so that I don't get nagged about an untrusted website every time I go to the JSS admin page.
Under Global Device Management > Public Key Infrastructure, I'm using the Built-in Certificate Authority to encrypt messages between the JSS and clients.