Install Certificates - Windows/Mac
Purpose
This solution manages the deployment of certificates to supported operating systems using NinjaOne custom fields and automated deployment conditions.
The solution supports the following platforms:
- Windows Workstations
- Windows Servers
- macOS
Users can centrally configure the certificate download URL, the certificate store or keychain location, and the operating systems on which the certificate should be deployed. The appropriate automation is then triggered automatically based on the endpoint's operating system and deployment configuration.
Key Capabilities
-
Platform Support
The solution is designed for Windows Workstations, Windows Servers, and macOS endpoints.
-
Operating System Selection
The cPVAL Enable Certificate Deployment custom field is used to select the operating systems on which certificate deployment should be enabled.
-
Windows Certificate Deployment
Windows certificates can be downloaded from a specified URL and imported into a defined Windows certificate store.
The certificate store can be customized, for example:
Cert:/LocalMachine/RootCert:/LocalMachine/MyCert:/CurrentUser/Root
If no store location is specified, the solution uses
Cert:/LocalMachine/Rootby default. -
macOS Certificate Deployment
macOS certificates can be downloaded from a specified URL and imported into a defined keychain.
The keychain can be customized, for example:
/System/Library/Keychains/SystemRootCertificates.keychain/Users/YourUsername/Library/Keychains/login.keychain/Library/Keychains/System.keychain
If no keychain is specified, the solution uses
/Library/Keychains/System.keychainby default. -
Centralized Configuration
Certificate deployment settings are managed through NinjaOne custom fields, allowing administrators to configure certificate deployment without modifying the automation scripts.
-
Automated Platform Targeting
Separate compound conditions are used to target Windows Workstations, Windows Servers, and macOS endpoints. This ensures that the appropriate certificate installation automation is executed on each platform.
Associated Content
Custom Fields
| Content | Purpose |
|---|---|
| cPVAL Enable Certificate Deployment | Custom field used to select the operating systems on which the certificate should be deployed. |
| cPVAL Win Certificate Download URL | Custom field used to specify the direct download URL of the certificate for Windows, for example: https://example.com/certificates/DNSFilter.cer. |
| cPVAL Win CertStoreLocation | Custom field used to specify the Windows certificate store into which the certificate is imported, for example: Cert:/CurrentUser/Root or Cert:/LocalMachine/My. If no value is specified, the default store location Cert:/LocalMachine/Root is used. |
| cPVAL MAC Certificate Download URL | Custom field used to specify the direct download URL of the certificate for macOS, for example: https://example.com/certificates/DNSFilter.cer. |
| cPVAL MAC CertStoreLocation | Custom field used to specify the macOS keychain into which the certificate is imported, for example: /System/Library/Keychains/SystemRootCertificates.keychain or /Users/YourUsername/Library/Keychains/login.keychain. If no value is specified, the default system-wide keychain /Library/Keychains/System.keychain is used, which applies the trusted root certificate to the entire system. |
Automation
| Name | Purpose |
|---|---|
| Install Certificate - Windows | Installs the certificate to the defined certificate store on Windows machines. If no store is defined, the certificate is imported into Cert:/LocalMachine/Root and applied to the entire system. |
| Install Certificate - Macintosh | Installs the certificate to the defined keychain on macOS machines. If no keychain is defined, the certificate is imported into /Library/Keychains/System.keychain and applied to the entire system. |
Compound Conditions
| Name | Purpose |
|---|---|
| Install Certificate - Workstations | Triggers the Automation - Install Certificate - Windows on Windows Workstations where certificate installation is enabled for Windows Workstations using the Custom Field - cPVAL Enable Certificate Deployment. |
| Install Certificate - Servers | Triggers the Automation - Install Certificate - Windows on Windows Servers where certificate installation is enabled for Windows Servers using the Custom Field - cPVAL Enable Certificate Deployment. |
| Install Certificate - Macintosh | Triggers the Automation - Install Certificate - Macintosh on macOS endpoints where certificate installation is enabled for Macintosh using the Custom Field - cPVAL Enable Certificate Deployment. |
Implementation
Step 1: Create the Following Custom Fields
Create all the custom fields listed below in NinjaOne. These are required for the solution to function correctly.
- cPVAL Enable Certificate Deployment
- cPVAL Win Certificate Download URL
- cPVAL Win CertStoreLocation
- cPVAL MAC Certificate Download URL
- cPVAL MAC CertStoreLocation
Step 2: Configure Certificate Deployment
Set the cPVAL Enable Certificate Deployment custom field to the option that matches the operating systems that should receive the certificate.
Then configure the certificate download URL and the certificate store or keychain location for each selected platform.
For Windows endpoints:
- Specify the certificate download URL in cPVAL Win Certificate Download URL.
- Optionally specify the certificate store in cPVAL Win CertStoreLocation.
- Optionally, specify the certificate store in cPVAL Win CertStoreLocation.
- If no certificate store is specified,
Cert:/LocalMachine/Rootis used.
For macOS endpoints:
- Specify the certificate download URL in cPVAL MAC Certificate Download URL.
- Optionally, specify the keychain in cPVAL MAC CertStoreLocation.
- If no keychain is specified,
/Library/Keychains/System.keychainis used.
Step 3: Create the Automations
Set up the following automations:
The Windows automation handles certificate installation on Windows Workstations and Windows Servers.
The Macintosh automation handles certificate installation on macOS endpoints.
Step 4: Create the Compound Conditions
Create the compound conditions that automatically target the appropriate endpoints:
- Compound Condition - Install Certificate - Workstations
- Compound Condition - Install Certificate - Servers
- Compound Condition - Install Certificate - Macintosh
The Workstations compound condition targets Windows Workstations where certificate deployment is enabled.
The Servers compound condition targets Windows Servers where certificate deployment is enabled.
The Macintosh compound condition targets macOS endpoints where certificate deployment is enabled.
FAQ
Q: Which platforms are supported?
The solution supports Windows Workstations, Windows Servers, and macOS endpoints.
Q: Which options are available in the cPVAL Enable Certificate Deployment custom field?
The cPVAL Enable Certificate Deployment custom field is a drop-down with the following options:
DisabledWindows WorkstationsWindows ServerWindows(Windows Workstations and Windows Servers)Windows Workstations and MacintoshMacintoshAll(Windows Workstations, Windows Servers, and macOS)
Q: What certificate file format should be used?
The solution is intended to download certificate files, such as
.cerfiles, from a direct download URL.
Q: Where is the certificate installed on Windows by default?
If no Windows certificate store is specified, the certificate is imported into
Cert:/LocalMachine/Root.
Q: Where is the certificate installed on macOS by default?
If no macOS keychain is specified, the certificate is imported into
/Library/Keychains/System.keychain.
Q: Can I specify a different Windows certificate store?
Yes. Use the cPVAL Win CertStoreLocation custom field to specify the required Windows certificate store, such as
Cert:/LocalMachine/MyorCert:/CurrentUser/Root. If no store is specified, the default location is used.
Q: Can I specify a different macOS keychain?
Yes. Use the cPVAL MAC CertStoreLocation custom field to specify the required macOS keychain. If no keychain is specified, the default location is used.
Q: Can the same certificate be deployed to both Windows and macOS?
Yes. Select an option in the cPVAL Enable Certificate Deployment custom field that includes both platforms (
Windows Workstations and MacintoshorAll). Windows and macOS use separate download URL fields, so enter the certificate URL in both cPVAL Win Certificate Download URL and cPVAL MAC Certificate Download URL.
Q: What happens when certificate deployment is disabled?
When the cPVAL Enable Certificate Deployment custom field is set to
Disabledor left empty, the endpoint is not targeted by any of the certificate deployment compound conditions, and the certificate installation automation is not triggered for that endpoint.
Q: Why is the automation not running on an endpoint?
Verify that:
- The endpoint is a supported Windows Workstation, Windows Server, or macOS endpoint.
- The cPVAL Enable Certificate Deployment custom field is set to an option that includes the endpoint's operating system.
- The appropriate Workstations, Servers, or Macintosh compound condition is applied to the endpoint's agent policy.
- A valid certificate download URL has been configured for the endpoint's platform.
- The configured certificate store or keychain location is valid.
- The endpoint can access the configured certificate download URL.
Q: Is any manual configuration required on the endpoint?
No. The solution uses the configured NinjaOne custom fields, automations, and compound conditions to deploy the certificate.
Changelog
2026-09-28
- Initial version of the document