ACME Managed Device Attestation - Saving certificate to Kerychain

Hello!

I’m testing certificate issuance using a locally running Smallstep step-ca ACME server with the device-attest-01 challenge.
I’ve created a custom MDM profile for this purpose. When I install the profile, the certificate is issued successfully, but it is not saved to the Keychain as stated in the documentation. I can only see the certificate via mdmclient or in the Wi-Fi settings dropdown menu.

Is this expected behavior, or are there additional settings that need to be included in the MDM profile?

ACME Managed Device Attestation - Saving certificate to Kerychain
 
 
Q