ACME Certificate (com.apple.security.acme)

com.apple.security.acme

The payload that configures Automated Certificate Management Environment (ACME) settings.

iOS(16.0)macOS(13.1)tvOS(16.0)visionOS(1.0)watchOS(9.0)
Branch: release

Settings (20)

SettingTypeRequiredDefaultManual InstallSupported OS
ACME directory URL
DirectoryURL
The directory URL of the ACME server. The URL must use the https scheme.
stringrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Client identifier
ClientIdentifier
A unique string identifying a specific device. The server may use this as an anti-replay code to prevent issuing multiple certificates. This identifier also indicates to the ACME server that the device has access to a valid client identifier issued by the enterprise infrastructure. This can help the ACME server determine whether to trust the device. Though this is a relatively weak indication because of the risk that an attacker can intercept the client identifier.
stringrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Key size
KeySize
The valid values for `KeySize` depend on the values of `KeyType` and `HardwareBound`. See those keys for specific requirements.
integerrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Key type
KeyType
The type of key pair to generate. Allowed values: - `RSA`: Specifies an RSA key pair. RSA key pairs need to have a `KeySize` that's a multiple of 8 in the range of 1024 through 4096 (inclusive), and `HardwareBound` needs to be `false`. - `ECSECPrimeRandom`: Specifies a key pair on the P-192, P-256, P-384, or P-521 curves as defined in FIPS Pub 186-4. `KeySize` defines the particular curve, which needs to be `192`, `256`, `384`, or `521`. Hardware bound keys only support values of `256` and `384`. > Note: > The key size is `521`, not `512`, even though the other key sizes are multiples of 64.
stringrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Hardware bound
HardwareBound
If `false`, the private key isn't bound to the device. If `true`, the private key is bound to the device. The Secure Enclave generates the key pair, and the private key is cryptographically entangled with a system key. This prevents the system from exporting the private key. If `true`, `KeyType` must be `ECSECPrimeRandom` and `KeySize` must be 256 or 384. macOS 14 on Apple silicon and Intel devices that have a T2 chip support setting this key to `true`. Older macOS versions or other Mac devices require this key but it must have a value of `false`.
booleanrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Subject
Subject
The device requests this subject for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues. The representation of a X.500 name represented as an array of OID and value. For example, `/C=US/O=Apple Inc./CN=foo/1.2.5.3=bar` corresponds to: `[ [ ["C", "US"] ], [ ["O", "Apple Inc."] ], ..., [ [ "1.2.5.3", "bar" ] ] ]` Dotted numbers can represent OIDs , with shortcuts for country (C), locality (L), state (ST), organization (O), organizational unit (OU), and common name (CN).
1 subkey
arrayrequired—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
Array inside ACME subject array
ACMESubjectArrayInnerArray
1 subkey
array—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─ └─
Subject array pair
ACMESubjectArrayPair
1 subkey
array—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─ └─ └─
ACME subject array pair item
ACMESubjectArrayPairItem
string—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Subject alt name
SubjectAltName
The Subject Alt Name that the device requests for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues.
4 subkeys
dictionaryoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
RFC 822 name
rfc822Name
The RFC 822 (email address) string.
stringoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
DNS name
dNSName
The DNS name.
stringoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
URI
uniformResourceIdentifier
The Uniform Resource Identifier.
stringoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
NT principal name
ntPrincipalName
The NT principal name. Use an other name OID set to `1.3.6.1.4.1.311.20.2.3`.
stringoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Key usage
UsageFlags
This value is a bit field. - Bit `0x01` indicates digital signature. - Bit `0x04` indicates encryption. The device requests this key for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues.
integeroptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Extended key usage
ExtendedKeyUsage
The value is an array of strings. Each string is an OID in dotted notation. For instance, `["1.3.6.1.5.5.7.3.2", "1.3.6.1.5.5.7.3.4"]` indicates client authentication and email protection. The device requests this field for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues.
1 subkey
arrayoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
└─
OID
OID
stringoptional—
✓Yes
iOS (16.0+)macOS (13.1+)tvOS (16.0+)visionOS (1.0+)watchOS (9.0+)
Attest
Attest
If `true`, the device provides attestations that describe the device and the generated key to the ACME server. The server can use the attestations as strong evidence that the key is bound to the device, and that the device has properties listed in the attestation. The server can use that as part of a trust score to decide whether to issue the requested certificate. When `Attest` is `true`, `HardwareBound` also needs to be `true`. macOS 14 supports setting this key to `true`. Older macOS versions require this key but it must have a value of `false`. See below for hardware requirements.
booleanoptionalfalse
✓Yes
watchOS (10.0+)
KeyIsExtractable
KeyIsExtractable
If `false`, the device tags the private key of the identity obtained through Automated Certificate Management Environment (ACME) as "non-extractable" in the keychain.
booleanoptionaltrue
✗No
Allow all apps access
AllowAllAppsAccess
If `true`, all apps have access to the private key.
booleanoptionalfalse
✗No

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information