• first downloading the certificate in the user enrollment process.
  • after installing the certificate you have to open up your keychain
  • search for "JSS" and open the certificate you just have installed
  • under "trust" choose "always trust" (I hope the translation is correct, I have German layout)
  • then close the certificate-windows and confirm with an admin user+password
  • You should now be able to install the MDM-Profile in the next steps