Set up SecureW2 JoinNow

SecureW2's JoinNow Connector PKI is a managed cloud CA. It issues certificates over SCEP or ACME, and its certificate templates can copy a URI SAN straight from the enrollment request, which is what carries the Firezone device identifier.

Before you begin

You need a SecureW2 tenant with access to Dynamic PKI and Integration Hub, and an MDM that enrolls certificates over SCEP.

1. Create the certificate authority

In Dynamic PKI → Certificate Authorities, select Add Certificate Authority. SecureW2 recommends a dedicated intermediate CA per integration rather than reusing one.

SettingValue
Generate CA ForDevice and User Authentication
TypeIntermediate CA
Generate viaInternal system (private key locked and non-exportable)
Key Size2048
Signature AlgorithmSHA-256

Managed devices do not need email notifications, so those can be disabled under Notifications.

2. Create the SCEP enrollment token

In Integration Hub → Device Management Platforms, select Add, then choose the type that matches your provisioning system:

Your provisioning systemType
Microsoft IntuneIntune CA Partner
Jamf Pro, Iru, or another MDMSCEP (Multi-Vendor) Enrollment Token

The multi-vendor token downloads a CSV holding the API secret and the Enrollment URL. Those are the SCEP challenge and SCEP URL your MDM profile needs.

The CSV is downloaded only once, when the token is created. Store it before leaving the page.

3. Create the certificate template

In Dynamic PKI → Certificate Authorities → Certificate Templates, select Add Certificate Template and set the values Firezone requires.

FieldValue
SubjectCN=dev.firezone.device-trust
SAN: URI${/csr/san/uniformresourceidentifier}
Extended Key Usage: Use Certificate ForClient Authentication

Two of these differ from SecureW2's own integration examples, for reasons specific to Firezone:

  • The subject is a literal, not a variable. SecureW2's guides use expressions like CN=${/device/clientId:/csr/subject/commonname}. Firezone selects an identity by its subject and requires exactly CN=dev.firezone.device-trust on every device, so enter that fixed string with no substitution.
  • The URI field carries the device identity. The ${/csr/san/uniformresourceidentifier} expression copies the URI SAN from the enrollment request into the issued certificate, which is how a value like firezone://serial/C02ABC123 reaches Firezone. Leave the other SAN fields unset unless something else needs them.

4. Configure your MDM's SCEP profile

Point the profile at the Enrollment URL and API secret from step 2, select the template from step 3, and have the profile request a supported device identifier as a URI SAN. The provider guides for Intune, Iru and Jamf Pro give the variable syntax each one uses to populate it.

Inspect an issued certificate before deploying broadly, and confirm it carries both the fixed common name and the URI SAN with a real device value. A profile can look correct while the template rewrites the subject or drops the requested SAN.

5. Collect the CA certificates

Export the root and intermediate CA certificates from your SecureW2 tenant. These are the files you add to Firezone.

Next step

Add the root and intermediate public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.


Need help? See all support options.