We are looking at rolling out SCEP Configuration Profiles for our iOS devices (and macOS devices...but for now, we're focusing on iOS). There is a definite lack of information out there on doing this, so I am curious if anyone has been able to successfully implement it?
We have created an iOS Configuration Profile, with the SCEP payload configured as follows...
URL
The base URL for the SCEP Server
http://scepserver.domain.org/certsrv/mscep/mscep.dll
Name
The name of the instance: CA-IDENT
NAME-NDES-MSCEP-RA
Display "Redistribute Profile" setting for this profile
*Display a setting in the General payload that allows you to choose when you want to automatically redistribute this profile
Unchecked
Subject
Representation of a X.500 name (e.g. O=CompanyName, CN=Foo)
CN=$DEVICENAME,O=Organization Name
Subject Alternative Name Type
The type of a subject alternative name
DNS Name
Subject Alternative Name Value
The value of a subject alternative name
Blank
NT Principal Name
An NT principal name for use in the certificate request
Blank
Retries
Number of times to retry after PENDING response
0
Retry Delay
Number of seconds to wait before each retry
0 Seconds
Challenge Type
Type of challenge password to use
Dynamic-Microsoft CA
URL to SCEP Admin
The URL of the page to use to retrieve the SCEP challenge
http://scepserver.domain.org/certsrv/mscep_admin/
Username
The username to use to log in to the SCEP Admin page
DOMAINSCEPAdminUsername
Password
The password to use to log in to the SCEP Admin page
SCEPAdminUsername_Password
Verify Password
SCEPAdminUsername_Password
Key Size
Key size in bits
2048
Use as digital signature
Checked
Use for key encipherment
Checked
Fingerprint
Enter hex string to be used as a fingerprint or use button to create fingerprint from certificate
Blank
However, with those settings (and whatever settings we have used...we have tested variations on the Subject name, Subject Alternative Name Value, Challenge Type, Key Size, etc.), when deploying the Configuration Profile to a iOS device, the JSS (Jamf Pro?) gives us the following error message...
The Registration Authority’s response is invalid.
So, has anyone been able to successfully deploy a SCEP payload to iOS devices? And if so, how the heck are you doing it!?
Thanks,
Steve
