This article describes a configuration example of the SCEP protocol in Protocol Gateway, using the provided enrollment templates file.
Simple Certificate Enrollment Protocol (SCEP) is a protocol that allows devices to easily enroll for a certificate by using a URL and a shared secret to communicate with a PKI.
Protocol Gateway only supports the enrollment protocols in RA mode, that is, a device RA key pair is used to protect the protocol messages. For use with devices that don't support RA mode, see more information in Use CMP or SCEP protocol in CA mode.
The elements that were imported during the initial configuration are marked with a black and yellow "under construction" bar, since they are not signed yet.
SCEP Registration and Enroll Procedure This token procedure uses the input view GPIV 8 - Save and Search SCEP Enrollment Registrations encrypted password.
Set SCEP properties
To set the properties for the SCEP protocols:
Open \Nexus\cm-gateway\conf\SCEP.properties for editing.
Modify the following properties:
Enable the SCEP protocol by setting start to true.
Set default.tokenprocedure to SCEP Registration and Enroll Procedure.
Set default.ra.keyfile to the Protocol Gateway RA token file and default.ra.password to the related PIN.