SCEP Profile

Prev Next

Kandji's SCEP Profile feature allows you to distribute and re-distribute certificates to Apple devices automatically.

Only static challenges are supported when using the SCEP Library Item.

Log in to your Kandji tenant before performing the next steps.

To add this Library Item to your Kandji Library, follow the steps outlined in the Library Overview article.

  1. Give your SCEP Library Item a name.

  2. Select the desired Blueprints.

  3. Input the base URL for your SCEP server.

  4. Optionally, put in a display Name, Challenge, and Fingerprint.

  5. Configure the Subject (optional), and Subject Alternative Name Type.

  6. Configure the Key Size and Key Usage

  7. Optionally, configure retry, access, export, expiration, and redistribution settings.

When the Automatic profile redistribution option is selected, Kandji will check the expiration date of the issued certificate and attempt to re-install the profile automatically to renew the certificate.  When using this option, the $PROFILE_UUID will be appended to the Subject in the request.

Using the Prevent the private key data from being extracted in the keychain option can prevent users from extracting the private key for the issued certificate.