JSS to Proxy the SCEP Certificate

jafuller
Contributor

We are not opening SCEP to off network devices (i.e. exposing SCEP to the internet). So we have run into an issue where certificates are being lost due to password changes (end users killing the login keychain which is where our VPN certificate lives).

Could the JSS serve as a proxy to SCEP? We don't want the JSS as an intermediate CA in our PKI. Rather we would like to be able to allow the JSS to request the certificate on behalf of the user/device and pass the resulting certificate down to the device over the air.

4 REPLIES 4

bbergstein
New Contributor III

This would be amazing... maybe this should be a feature request though instead of a discussion?

JPDyson
Valued Contributor

ERMAHGERD yes. I would love this.

JPDyson
Valued Contributor

So, out of curiosity, have you tried Settings -> Global Management Framework Settings -> Public Key Infrastructure? You can define your SCEP environment there, but I'm not sure what it buys you.

JPDyson
Valued Contributor