Posted on 04-29-2013 11:49 AM
We are not opening SCEP to off network devices (i.e. exposing SCEP to the internet). So we have run into an issue where certificates are being lost due to password changes (end users killing the login keychain which is where our VPN certificate lives).
Could the JSS serve as a proxy to SCEP? We don't want the JSS as an intermediate CA in our PKI. Rather we would like to be able to allow the JSS to request the certificate on behalf of the user/device and pass the resulting certificate down to the device over the air.
Posted on 04-29-2013 12:01 PM
This would be amazing... maybe this should be a feature request though instead of a discussion?
Posted on 04-29-2013 12:07 PM
ERMAHGERD yes. I would love this.
Posted on 04-30-2013 07:41 AM
So, out of curiosity, have you tried Settings -> Global Management Framework Settings -> Public Key Infrastructure? You can define your SCEP environment there, but I'm not sure what it buys you.
Posted on 05-01-2013 08:59 AM