public SSL certificate on Tomcat but still have to manually trust CA certificate

mallej
New Contributor III

Hello, as mentioned here untrusted root certificates installed manually on unsupervised iOS devices need to be manually trusted in Certificate Trust Settings during user-initiated enrollment.
So i obtained a publicly-trusted web server certificate from letsencrypt.org and upload the SSL certificate via Apache Tomcat settings in the JSS.
I assumed that this will stop the manual trust behavior but with no luck.
May there a technical problem or do i misunderstood the whole process?
aef1c5d417aa44aba661e8e111b983f8

1 REPLY 1

tuinte
Contributor III

While public, your root CA may not be inherently trusted by Apple/iOS 10, in which case you'd still need to manually trust it.

Here's Apple's list of trusted root certs for iOS 10.

I don't see Let's Encrypt on there.