Step 3 - Download the enrollment configuration file
Before you download the configuration file, you must upload the CA certificate that validates the identity certificate that a device presents at enrollment and renewal. Each time a CA certificate is uploaded for ZTA enrollment purposes, the ZTA enrollment configuration file is regenerated. The configuration file includes information about all CA certificates that have been uploaded and designated for ZTA enrollment.
You can download the configuration file from either of two locations:
- Navigate to Connect > End User Connectivity, click the Zero Trust Access or Virtual Private Network tab, then click the Cisco Secure Client button.
or
- Navigate to Connect > End User Connectivity, click the Zero Trust Access tab. In the Enrollment Methods section, click Manage. Download the file from the Use Certificates section.
The configuration file name is orgID_ZTA_Enroll_Cert.json.