I've been trying to slowly move away from binding my Macs to Active Directory and using tools like NoMAD. I want to be able to use SCEP in a ConfigurationProfile to request a cert with a challenge (pre-shared) password, but haven't been able to get it working. I'm looking to get the Mac connected (without using a users creds for shared computers) I get as far as the profile erring out with
Unable to create X509 name from 'Subject' parts in SCEP payload
Has anyone got this working? Does it even work at all?
Here are the details of my macOS Configuration Profile:
macOS Configuration Profile
Level: Computer Level
Distribution: Automatic
Network Payload
Auto Join: Yes
Security Type: WPA2 Enterprise
Protocols: TLS
Identity Certificate: SCEP (Cert_Name)
QOS: Mark All Apps
Trusted Certificates: Root Internal CA
Certificate Payload
Certificates: Root CA
SCEP Payload
URL: http://path_to_ca.fqdn/certsrv/mscep/mscep.dll
Name: Cert_Name
Redistribute Profile: 14 Days
Subject: CN=$SERIALNUMBER $PROFILE_IDENTIFIER,OU=IT,O=Org_Name,L=City_Name,S=STATE_NAME,C=US
Subject Alternative Name: None
Challenge Type: Static
Retries: 3
Retry Delay: 3
Certificate Expiration Notification Threshold: 14
Key Size: 2048 (Admin set it to this in the Certificate Template)
