We are not opening SCEP to off network devices (i.e. exposing SCEP to the internet). So we have run into an issue where certificates are being lost due to password changes (end users killing the login keychain which is where our VPN certificate lives).
Could the JSS serve as a proxy to SCEP? We don't want the JSS as an intermediate CA in our PKI. Rather we would like to be able to allow the JSS to request the certificate on behalf of the user/device and pass the resulting certificate down to the device over the air.