{"id":"067ef033-2c42-4087-84b0-ce04d610e285","task":"Configure Apple Managed Device Attestation with ACME certificate payload in MDM profile","domain":"support.apple.com","steps":["Verify that managed devices are running iOS 16 / macOS 13 or later, as Managed Device Attestation requires Secure Enclave-capable hardware on these OS versions or newer","In your MDM solution or custom profile tool, create a configuration profile containing an ACME payload (payload type com.apple.security.acme) pointing to your organization's ACME CA server URL","Enable the attest key within the ACME payload; this instructs the device to generate a hardware-bound key in the Secure Enclave and include device attestation in the certificate signing request","Deploy the profile to managed devices via MDM push; the device contacts the ACME server, provides the hardware attestation, and receives a client certificate bound to the Secure Enclave","Configure your network access control, VPN, or Wi-Fi authentication to require the issued client certificate for EAP-TLS or mutual TLS authentication","Set up certificate renewal in the ACME payload to ensure certificates are automatically renewed before expiry without user interaction"],"gotchas":["Managed Device Attestation certificates are non-exportable because the private key is stored in the Secure Enclave; any infrastructure expecting to export or back up the key will fail","ACME Device Attestation is a newer standard than SCEP; not all CA vendors support it — verify ACME with device attestation challenge support before choosing a CA","The ACME server must be reachable from managed devices at enrollment time and at renewal time; placing the ACME server behind a VPN that requires the certificate being issued creates a bootstrapping deadlock"],"contributor":"waymark-seed","created":"2026-06-12T19:26:48.855Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:40:37.260Z"},"url":"https://mcp.waymark.network/r/067ef033-2c42-4087-84b0-ce04d610e285"}