Skip to main content

Install Certificates - Windows/Mac

Purpose​

This solution manages the deployment of certificates to supported operating systems using NinjaOne custom fields and automated deployment conditions.

The solution supports the following platforms:

  • Windows Workstations
  • Windows Servers
  • macOS

Users can centrally configure the certificate download URL, the certificate store or keychain location, and the operating systems on which the certificate should be deployed. The appropriate automation is then triggered automatically based on the endpoint's operating system and deployment configuration.

Key Capabilities​

  1. Platform Support

    The solution is designed for Windows Workstations, Windows Servers, and macOS endpoints.

  2. Operating System Selection

    The cPVAL Enable Certificate Deployment custom field is used to select the operating systems on which certificate deployment should be enabled.

  3. Windows Certificate Deployment

    Windows certificates can be downloaded from a specified URL and imported into a defined Windows certificate store.

    The certificate store can be customized, for example:

    • Cert:/LocalMachine/Root
    • Cert:/LocalMachine/My
    • Cert:/CurrentUser/Root

    If no store location is specified, the solution uses Cert:/LocalMachine/Root by default.

  4. macOS Certificate Deployment

    macOS certificates can be downloaded from a specified URL and imported into a defined keychain.

    The keychain can be customized, for example:

    • /System/Library/Keychains/SystemRootCertificates.keychain
    • /Users/YourUsername/Library/Keychains/login.keychain
    • /Library/Keychains/System.keychain

    If no keychain is specified, the solution uses /Library/Keychains/System.keychain by default.

  5. Centralized Configuration

    Certificate deployment settings are managed through NinjaOne custom fields, allowing administrators to configure certificate deployment without modifying the automation scripts.

  6. Automated Platform Targeting

    Separate compound conditions are used to target Windows Workstations, Windows Servers, and macOS endpoints. This ensures that the appropriate certificate installation automation is executed on each platform.

Associated Content​

Custom Fields​

ContentPurpose
cPVAL Enable Certificate DeploymentCustom field used to select the operating systems on which the certificate should be deployed.
cPVAL Win Certificate Download URLCustom field used to specify the direct download URL of the certificate for Windows, for example: https://example.com/certificates/DNSFilter.cer.
cPVAL Win CertStoreLocationCustom field used to specify the Windows certificate store into which the certificate is imported, for example: Cert:/CurrentUser/Root or Cert:/LocalMachine/My. If no value is specified, the default store location Cert:/LocalMachine/Root is used.
cPVAL MAC Certificate Download URLCustom field used to specify the direct download URL of the certificate for macOS, for example: https://example.com/certificates/DNSFilter.cer.
cPVAL MAC CertStoreLocationCustom field used to specify the macOS keychain into which the certificate is imported, for example: /System/Library/Keychains/SystemRootCertificates.keychain or /Users/YourUsername/Library/Keychains/login.keychain. If no value is specified, the default system-wide keychain /Library/Keychains/System.keychain is used, which applies the trusted root certificate to the entire system.

Automation​

NamePurpose
Install Certificate - WindowsInstalls the certificate to the defined certificate store on Windows machines. If no store is defined, the certificate is imported into Cert:/LocalMachine/Root and applied to the entire system.
Install Certificate - MacintoshInstalls the certificate to the defined keychain on macOS machines. If no keychain is defined, the certificate is imported into /Library/Keychains/System.keychain and applied to the entire system.

Compound Conditions​

NamePurpose
Install Certificate - WorkstationsTriggers the Automation - Install Certificate - Windows on Windows Workstations where certificate installation is enabled for Windows Workstations using the Custom Field - cPVAL Enable Certificate Deployment.
Install Certificate - ServersTriggers the Automation - Install Certificate - Windows on Windows Servers where certificate installation is enabled for Windows Servers using the Custom Field - cPVAL Enable Certificate Deployment.
Install Certificate - MacintoshTriggers the Automation - Install Certificate - Macintosh on macOS endpoints where certificate installation is enabled for Macintosh using the Custom Field - cPVAL Enable Certificate Deployment.

Implementation​

Step 1: Create the Following Custom Fields​

Create all the custom fields listed below in NinjaOne. These are required for the solution to function correctly.

Step 2: Configure Certificate Deployment​

Set the cPVAL Enable Certificate Deployment custom field to the option that matches the operating systems that should receive the certificate.

Then configure the certificate download URL and the certificate store or keychain location for each selected platform.

For Windows endpoints:

For macOS endpoints:

Step 3: Create the Automations​

Set up the following automations:

The Windows automation handles certificate installation on Windows Workstations and Windows Servers.

The Macintosh automation handles certificate installation on macOS endpoints.

Step 4: Create the Compound Conditions​

Create the compound conditions that automatically target the appropriate endpoints:

The Workstations compound condition targets Windows Workstations where certificate deployment is enabled.

The Servers compound condition targets Windows Servers where certificate deployment is enabled.

The Macintosh compound condition targets macOS endpoints where certificate deployment is enabled.

FAQ​

Q: Which platforms are supported?​

The solution supports Windows Workstations, Windows Servers, and macOS endpoints.

Q: Which options are available in the cPVAL Enable Certificate Deployment custom field?​

The cPVAL Enable Certificate Deployment custom field is a drop-down with the following options:

  • Disabled
  • Windows Workstations
  • Windows Server
  • Windows (Windows Workstations and Windows Servers)
  • Windows Workstations and Macintosh
  • Macintosh
  • All (Windows Workstations, Windows Servers, and macOS)

Q: What certificate file format should be used?​

The solution is intended to download certificate files, such as .cer files, from a direct download URL.

Q: Where is the certificate installed on Windows by default?​

If no Windows certificate store is specified, the certificate is imported into Cert:/LocalMachine/Root.

Q: Where is the certificate installed on macOS by default?​

If no macOS keychain is specified, the certificate is imported into /Library/Keychains/System.keychain.

Q: Can I specify a different Windows certificate store?​

Yes. Use the cPVAL Win CertStoreLocation custom field to specify the required Windows certificate store, such as Cert:/LocalMachine/My or Cert:/CurrentUser/Root. If no store is specified, the default location is used.

Q: Can I specify a different macOS keychain?​

Yes. Use the cPVAL MAC CertStoreLocation custom field to specify the required macOS keychain. If no keychain is specified, the default location is used.

Q: Can the same certificate be deployed to both Windows and macOS?​

Yes. Select an option in the cPVAL Enable Certificate Deployment custom field that includes both platforms (Windows Workstations and Macintosh or All). Windows and macOS use separate download URL fields, so enter the certificate URL in both cPVAL Win Certificate Download URL and cPVAL MAC Certificate Download URL.

Q: What happens when certificate deployment is disabled?​

When the cPVAL Enable Certificate Deployment custom field is set to Disabled or left empty, the endpoint is not targeted by any of the certificate deployment compound conditions, and the certificate installation automation is not triggered for that endpoint.

Q: Why is the automation not running on an endpoint?​

Verify that:

  • The endpoint is a supported Windows Workstation, Windows Server, or macOS endpoint.
  • The cPVAL Enable Certificate Deployment custom field is set to an option that includes the endpoint's operating system.
  • The appropriate Workstations, Servers, or Macintosh compound condition is applied to the endpoint's agent policy.
  • A valid certificate download URL has been configured for the endpoint's platform.
  • The configured certificate store or keychain location is valid.
  • The endpoint can access the configured certificate download URL.

Q: Is any manual configuration required on the endpoint?​

No. The solution uses the configured NinjaOne custom fields, automations, and compound conditions to deploy the certificate.

Changelog​

2026-09-28​

  • Initial version of the document