If you use your provisioning server with the HTTPS protocol and a private certificate authority, upload the root certificate of that certificate authority. If you use a public certificate authority, there is no need to upload a root certificate. You can upload the certificate from the Profile Management section. The certificate is used to establish a secure connection between the device and the provisioning server.
Important:
Device Enrollment Services recommends to use an explicit FQDN in the certificate because some devices might not accept a certificate containing FQDNs with wildcards. For example, *.domain.com.