SCEP

Edit

Description



SCEP Server description



Deployment Scope



Certificate deployment scope: Current Device vs User



SCEP Server URLs



One or more servers that issue certificates through SCEP



Subject



Representation of a X.500 name. E.g. “C=US, O=Microsoft Corporation, CN=foo, 1.2.5.3=bar”



Subject alternative names



Type



Email address



DNS



URI



User Principal Name (UPN)



CA Fingerprint



The SHA1 fingerprint of the Certificate Authority certificate. E.g. 31:8F:1E:78:5C:D5:12:9F:7E:3B:AD:F3:1C:C0:19:03:96:43:A9:E5



Validity period units



Days, Months or Years



Validity period



Challenge



Used as the pre-shared secret for automatic enrollment



Retries



The number of times the device should retry if the server sends a PENDING response. The default value is 5. Maximum value is 30.



Retry delay



Number of minutes to wait before retry. The default value is 5. The minimum value is 1.



Key size



Key size in bits



Hash algorithm



Hash algorithm family



Key usage



The key usage extension defines the purpose (e.g., encipherment, signature) of the key contained in the certificate. At least one of the “Digital signature” or “Key encipherment” needs to be selected.



Extended key usage



Specifies extended key usages.Subject to SCEP server configuration. Specify the list of corresponding OIDs, e.g. 1.3.6.1.5.5.7.3.2 (Client Authentication)



Key location



The Key Storage Provider to install the private key to.



TPM. Fail if no TPM present



TPM. If no TPM present, fallback to Software KSP



Software Key Storage Provider



Windows Hello for Business



Container name



Specifies the Windows Hello for Business (formerly known as Microsoft Passport for Work) container name.



PIN prompt text



Specifies the custom text to show on the Windows Hello for Business PIN prompt during certificate enrollment.


This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.