PCI - Mac Imaging and Deployment
Overview of deploying Apple macOS devices in PCI
- Assign device to PCI MDM in ASM
- Boot device and enroll in WS1
- Log in with "localadmin"
- Connect to adminvpn
- Run BigFix baseline
- Run certificate enrollment
- In a non-Safari browser sign in using AD credentials: https://pci-one-ca-01.pci.wisc.edu/certsrv
- Request a certificate, advanced certificate request
- Open Keychain, select Keychain Access in the top menu, select Certificate Assistant, and then Request a Certificate From a Certificate Authority
- In the menu enter the following
- Email: pci-wiscit@doit.wisc.edu
- Request a certificate, advanced certificate request
- Common Name: WPT-SERIAL aka the computer name
- Save to disk
- Open the CSR in a text editor and copy/paste into the Saved Request box in your web browser
- From the dropdown select DS - Mac Computer
- Submit
- In a non-Safari browser sign in using AD credentials: https://pci-one-ca-01.pci.wisc.edu/certsrv
- Select DER encoded and Download certificate chain
- Add the full cert chain to Keychain by double-clicking on it but make sure to select the System Keychain
- Very Important! When you first try to connect to remotepcs.pci.wisc.edu you will get a permissions popup that GP is trying to access the cert; make sure you select "Always Allow"