I'm in the process of trying to creating a slimmed download mobileconfig file so that my machines that are running 10.13 will have the FV key escrowed. I've followed the recipe provided from this link however I've done everything down to step 7. At this point I got totally confused and frustrated when it comes to certificates and keys. From what I understand I can sign this mobileconfig using either a signing certificate from the Apple Dev. site or I can generate one using the JSS CA. I would much rather use the one provided from the JSS since my machines are already trusting this. In saying that I'm having a time getting the items in order so that I can accomplish this. If I log into my JSS Cloud instance and make my way over to the PKI section I can easily down the CA there. If I import this into my keychain and then try to sign the mobileconfig I get "Could not find signing identity for name: blah blah blah".
From what I understand you need both a self-signing certificate and the private keys to in order to sign something. Am I correct in this?
If someone could provide me with some guiadance on this I would greatly appreciate it!
