Skip to main content
Question

CA cert not trusted after PreStage (macOS 26.4)

  • April 8, 2026
  • 1 reply
  • 29 views

Forum|alt.badge.img+3

JAMF Pro -  Running into something weird with newly prestaged Macs and not sure where to start.

After PreStage enrollment, our internal CA cert. is getting installed, but it shows as not trusted in the System keychain. We can manually trust it and it’s fine after that.

This wasn’t happening before — machines on 26.2 were fine. Started noticing it on 26.4.

At the same time, GlobalProtect won’t connect on these machines. It just throws:

“network connection is unreachable or portal is unresponsive”

1 reply

MattAebly
Forum|alt.badge.img+17
  • Employee
  • April 8, 2026

Hello, ​@MoJo,

If you are using an internal CA sever to generate device certs, the trust chain might be broken somewhere along the way. Could you check if the Root CA is invalid/expired?