User-scoped certificates on macOS need a login keychain (#39364)

Discovered by `pingali`:
https://fleetdm.slack.com/archives/C050XE4CQNA/p1770181946960079?thread_ts=1769555555.606569&cid=C050XE4CQNA
This commit is contained in:
Noah Talerman
2026-02-24 09:12:17 -05:00
committed by GitHub
parent 3d554a52de
commit 642e9cfc35
@@ -712,6 +712,8 @@ You can deploy a user-scoped certificate on macOS and Windows hosts using a user
2. Create a certificate [configuration profile](#example-configuration-profiles). For Windows, replace `./Device` with `./User` in all `<LocURI>` elements. For macOS, set `PayloadScope` to `User`.
3. In Fleet, navigate to **Controls > OS settings > Custom settings** and upload the configuration profile you created.
For macOS hosts, user-scoped certificates only work if the `login` keychain is unlocked. If it's locked, MDM commands to install the certificate configuration profile will always return `NotNow`. To check whether the `login` keychain is unlocked, open Keychain Access on the Mac. An unlocked icon should appear to the left of the `login` keychain under **Default keychains**. If it's locked, right-click on the `login` keychain to unlock it.
### Editing ceritificate configuration profiles on Apple (macOS, iOS, iPadOS) hosts
When you edit a certificate configuration profile for Apple hosts, via GitOps, a new certificate will be added to each hosts' Keychain and the old certificate will be removed. It takes a couple minutes for the old certificate to be removed.