How-To: Issue SCEP Certificates in iMazing Profile Editor
EZCA can now automatically generate an Apple Configuration Profile (.mobileconfig file) for you. You can download it directly from your EZCA SCEP CA, under View Requirements, without the need to manually create one in iMazing Profile Editor. You can push this auto-generated file to your devices directly, or edit it for further customization within iMazing Profile Editor.
Overview - What is iMazing Profile Editor?
iMazing Profile Editor is an application for macOS and Windows that allows administrators to configure and deploy iOS, iPadOS, and tvOS devices in bulk. It provides tools for creating and installing configuration profiles, including SCEP certificates, on Apple devices.
Does iMazing Profile Editor Support SCEP Certificates?
Yes. iMazing Profile Editor has built-in support for creating and deploying SCEP certificates to Apple devices. You can use iMazing Profile Editor to create a configuration profile that includes a trusted Certificate and SCEP payload, which can then be installed on your devices to issue SCEP certificates from your EZCA SCEP CA.
When using iMazing Profile Editor to issue SCEP certificates, you can use Apple’s built-in variables to dynamically populate the Subject and Subject Alternative Name (SAN) fields of the issued certificates with device-specific information, such as the device’s hardware UUID or hostname. This allows for more personalized certificates that can be used for a variety of use cases, such as Wi-Fi or VPN authentication.
Can I Use iMazing Profile Editor-Issued SCEP Certificates for Wi-Fi or VPN?
Yes! Once you issue SCEP certificates to your devices using iMazing Profile Editor, you can use them like any X.509 certificate. This means you can use them for Wi-Fi authentication, VPN authentication, or any other use case that requires a client certificate. The use of Apple’s built-in variables allows for more personalized certificates that can be tailored to specific devices.What Types of Apple Devices Can I Issue SCEP Certificates To with iMazing Profile Editor?
iMazing Profile Editor supports managing iOS, iPadOS, tvOS, and macOS devices. This means you can issue SCEP certificates to iPhones, iPads, Apple TVs, and Macs using the custom profile method described in this guide.How to Configure iMazing SCEP Certificate Authority - Step by Step Guide
The following steps will walk you through the process of configuring iMazing to issue SCEP certificates using your EZCA SCEP CA.
Prerequisites for Configuring iMazing Profile Editor with SCEP
- You will need a macOS or Windows device with iMazing Profile Editor installed to create the custom profile.
- You will need an EZCA SCEP CA set up and ready to issue certificates.
How to Download Your Root and/or SCEP CA Certificates from EZCA
To establish trust for your SCEP certificates, you will need to download and later push the CA certificate(s) for your SCEP CA to your devices. If your SCEP CA is a subordinate CA, you will need to download both the root and SCEP CA certificates. If your SCEP CA is a root CA, you will only need to download the SCEP CA certificate.
-
Navigate to your EZCA portal and sign in as a PKI Administrator.
-
Click on the Certificate Authorities tab and scroll to your SCEP CA.
-
Click on the View Requirements button for your SCEP CA.
-
Scroll down to the CA Locations section and click on the Download Certificate button for your CA.
How to Enable Static SCEP Challenge in Your EZCA SCEP CA
Before you can create a custom profile for SCEP in PRODUCT-NAME, you need to ensure that your EZCA SCEP CA is configured to use a static challenge.
-
Navigate to your EZCA portal and sign in as a PKI Administrator.
-
Click on the Certificate Authorities tab and scroll to your SCEP CA.
-
Click on View Requirements for your SCEP CA.
-
Check the box for Enable SCEP Static Challenge and click Save Changes. You will now see your Static Challenge SCEP URL and SCEP Challenge:
How to Create a Configuration Profile in iMazing Profile Editor for SCEP
-
Download and install iMazing Profile Editor.
-
Open iMazing Profile Editor, and click on File → New Profile to create a new configuration profile.
-
Fill out the General section with a name and description for the profile.
-
Click on the Root Certificate section and then click on the Add Payload button to add a new certificate payload.
-
Select the Root CA certificate you downloaded from EZCA and upload it to the profile. This will ensure that the Root CA certificates are pushed to the devices and that they trust the SCEP Root CA.
-
Repeat the process to upload the CA certificate if your SCEP CA is a subordinate CA.
-
Next, click on the SCEP section and click on the Add Payload button to add a new SCEP payload.
-
Copy the Static Challenge SCEP URL from your EZCA portal and paste it into the URL field in iMazing Profile Editor.
-
Copy the Challenge from EZCA and paste it into the Challenge field.
-
Configure the remaining fields:
-
Subject: Use a static value or Apple’s built-in variables (e.g.
CN=%HardwareUUID%) -
Retries: 3
-
Retry Delay: 30
-
Key Size: Set as 2048 or higher.
-
Key Usage: Set as Both signing and encryption.
-
-
You should now have a complete SCEP configuration in your custom profile:
-
Click File → Save to save the profile to your device as a .mobileconfig file.
How to Install a Configuration Profile on macOS
Now that you have created a configuration profile for SCEP in iMazing Profile Editor, you can install it on your device.
When a profile is manually installed on a device, it will issue the certificate to the User’s keychain and not the System keychain. Only MDM solutions can issue certificates to the System keychain. This means that if you manually install the profile created in iMazing Profile Editor, the SCEP certificate will be issued to the User keychain and will only be available for that user. If you want the certificate to be available system-wide, you will need to upload the profile to an MDM solution like Intune or Jamf and deploy it to your devices.
-
Double-click the .mobileconfig file you saved from iMazing Profile Editor.
-
Open Settings. In the top-right of the page, click Profile Downloaded. You will see the profile you just created in iMazing Profile Editor under Downloaded.
-
Double-click on the profile to view its contents and click Install….
-
Your trusted certificates will now be installed, and the device will attempt to enroll in SCEP and request a certificate from your EZCA SCEP CA.
How to Verify Your Apple Devices Received the SCEP Certificate
To verify that your devices have received the SCEP certificate, you can check the device’s certificate store via the Keychain Access app on macOS.
-
Open the Keychain Access app on your macOS device.
-
In the left sidebar, select login.
-
Select the Certificates category.
-
You will now see both the CA certificate(s) you uploaded in the profile and the SCEP certificate issued to the device.
Enjoying EZCA? Leave Us a Review!
We hope you’re enjoying using EZCA to issue your SCEP certificates! If you have a moment, we would greatly appreciate it if you could leave us a review on G2. Your feedback helps other IT professionals discover EZCA and helps us continue to improve our service. Thank you for your support!