Set up SecureW2 JoinNow
SecureW2's JoinNow Connector PKI is a managed cloud CA. It issues certificates over SCEP or ACME, and its certificate templates can copy a URI SAN straight from the enrollment request, which is what carries the Firezone device identifier.
Before you begin
You need a SecureW2 tenant with access to Dynamic PKI and Integration Hub, and an MDM that enrolls certificates over SCEP.
1. Create the certificate authority
In Dynamic PKI → Certificate Authorities, select Add Certificate Authority. SecureW2 recommends a dedicated intermediate CA per integration rather than reusing one.
| Setting | Value |
|---|---|
| Generate CA For | Device and User Authentication |
| Type | Intermediate CA |
| Generate via | Internal system (private key locked and non-exportable) |
| Key Size | 2048 |
| Signature Algorithm | SHA-256 |
Managed devices do not need email notifications, so those can be disabled under Notifications.
2. Create the SCEP enrollment token
In Integration Hub → Device Management Platforms, select Add, then choose the type that matches your provisioning system:
| Your provisioning system | Type |
|---|---|
| Microsoft Intune | Intune CA Partner |
| Jamf Pro, Iru, or another MDM | SCEP (Multi-Vendor) Enrollment Token |
The multi-vendor token downloads a CSV holding the API secret and the Enrollment URL. Those are the SCEP challenge and SCEP URL your MDM profile needs.
The CSV is downloaded only once, when the token is created. Store it before leaving the page.
3. Create the certificate template
In Dynamic PKI → Certificate Authorities → Certificate Templates, select Add Certificate Template and set the values Firezone requires.
| Field | Value |
|---|---|
| Subject | CN=dev.firezone.device-trust |
| SAN: URI | ${/csr/san/uniformresourceidentifier} |
| Extended Key Usage: Use Certificate For | Client Authentication |
Two of these differ from SecureW2's own integration examples, for reasons specific to Firezone:
- The subject is a literal, not a variable. SecureW2's guides use
expressions like
CN=${/device/clientId:/csr/subject/commonname}. Firezone selects an identity by its subject and requires exactlyCN=dev.firezone.device-truston every device, so enter that fixed string with no substitution. - The URI field carries the device identity. The
${/csr/san/uniformresourceidentifier}expression copies the URI SAN from the enrollment request into the issued certificate, which is how a value likefirezone://serial/C02ABC123reaches Firezone. Leave the other SAN fields unset unless something else needs them.
4. Configure your MDM's SCEP profile
Point the profile at the Enrollment URL and API secret from step 2, select the template from step 3, and have the profile request a supported device identifier as a URI SAN. The provider guides for Intune, Iru and Jamf Pro give the variable syntax each one uses to populate it.
Inspect an issued certificate before deploying broadly, and confirm it carries both the fixed common name and the URI SAN with a real device value. A profile can look correct while the template rewrites the subject or drops the requested SAN.
5. Collect the CA certificates
Export the root and intermediate CA certificates from your SecureW2 tenant. These are the files you add to Firezone.
Next step
Add the root and intermediate public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.
Need help? See all support options.