Skip to main content
Configure the fleet before installing the first device. In the Bifrost dashboard, go to Edge Control → Edge Settings.
Bifrost Edge Settings page

1. Set up the certificate authority

Edge uses the configured certificate authority (CA) to inspect TLS traffic for configured AI domains. The CA certificate must be trusted by each device. Its private key remains on the Bifrost server for current agents, which request short-lived leaf certificates from the server.
  1. In Certificate Authority, select Generate CA.
  2. Generate the certificate.
  3. Store the displayed private key securely. It is shown in the generation result and is not available from the active-certificate view afterward.
After either path, confirm that the CA shows Active and record its SHA-256 fingerprint. The fingerprint is the value administrators use to confirm that a device or MDM profile contains the active certificate.
Replacing the CA changes the certificate that devices must trust. A macOS MDM deployment must receive an updated trusted-root profile for the replacement certificate. After the new CA is trusted, restart every affected computer before testing or resuming governed traffic. The restart is required for the CA certificate change to take effect.

2. Review first-rollout settings

Save any changes before continuing.

3. Download the CA for MDM

If you are deploying to macOS with MDM, select Download .crt from the active certificate view. You will use that exact certificate in the device-scoped trusted-root profile. Direct installations do not require you to download the CA separately. The agent receives it from Bifrost after sign-in and establishes trust as described in the direct-installation guide.

Choose the installation path