Redtrust on Mac, iPhone, and iPad
Overview
Redtrust protects and controls your digital certificates on Mac, iPhone, and iPad with the same model as on every other platform: the private key stays under custody, every use generates an event, and policies decide who can use each certificate. This page brings together the specific differences of macOS and iOS so that you can design your policies and your deployments with them in mind.
Operating system restrictions explain most of these differences. To understand which security layer Redtrust controls and what falls outside its reach, see How Redtrust controls certificate use.
Installation
On macOS, you get the agent's DMG file from your Redtrust provider. On iOS, you download the Redtrust agent from the App Store. See the installation guide for system requirements and full instructions.
Authentication
The macOS and iOS agents support the following authentication modes:
- Local Users: Users created in the Redtrust local domain.
- SAML 2.0: Authentication through an Identity Provider. See IdP integration with SAML 2.0.
- OAuth 2.0: Authentication through an Identity Provider that supports OAuth 2.0.
Active Directory and LDAP authentication aren't available on these platforms.
Certificate use
Redtrust integrates with the Apple Keychain, so applications that use the system certificate store access your certificates with no extra configuration. You don't need to install a browser extension on these platforms.
| Feature | macOS | iOS |
|---|---|---|
| Keychain integration | Yes | Yes |
| Browser extension | Not required | Not required |
| PKCS#11 module | Yes | No |
| Certificates in Firefox | Yes, through the PKCS#11 module | No |
| Java applications, such as AutoFirma or PJe Office | Yes, through the PKCS#11 module | No |
To load the PKCS#11 module in Firefox, see the installation guide.
Certificate selection
The agent shows the All available certificates list, where you can choose which certificates you want to use. If you don't select any, all of them are considered enabled by default. Turn on Remember selection to keep your selection the next time you start the agent.
Policies
For a user to be able to use a certificate on macOS or iOS, the policy must have Enable for Mac OS turned on. Although its name mentions only Mac OS, the option applies to both platforms. If it's off, the policy doesn't apply even if the user and the certificate match.
On these platforms you can't limit certificate use by application or by site, because the agent doesn't report the process or the URL. The application and site groups that you add to the policy have no effect. A single policy can apply to users on several platforms: application and site groups still apply to Windows users.
For the rest of the wizard options, see Policies.
User PIN and usage reason
The macOS and iOS agents don't support the user PIN or the usage reason yet. If a certificate requires a PIN or a usage reason, the agent shows (not available) next to its alias, the certificate can't be selected, and it can't be used. To use a certificate on these platforms, set it up without a user PIN or a usage reason. See Set and change user PIN.
Auditing
Every certificate use generates an event, just as on every other platform. The event context includes the platform, the applied policy, and the agent ID.
Due to Apple restrictions, the event doesn't record the URL or the process where the certificate was used. For more details, see Events.
Agent settings
On macOS, go to Redtrust Agent in the menu bar and select Settings. On iOS, open the system Settings and select Redtrust Agent. On both platforms you can configure the following:
- Allow download logs: Enables downloading the agent logs.
- Log level: Sets the level of detail of the logs. The values are
NONE,LOW, andHIGH. - Show config screen on restart: Shows the configuration screen the next time you start the agent, so that you can modify its parameters.
Was this page helpful?