How-To: Issue SCEP Certificates in SimpleMDM

Learn how to issue Apple Configuration profiles with SCEP certificates to devices using SimpleMDM and an EZCA SCEP CA

How to Configure SimpleMDM SCEP Certificate Authority - Step by Step Guide

The following steps will walk you through the process of creating an Apple Configuration Profile with SCEP certificates and configuring SimpleMDM to issue the .mobileconfig file.

How to Create An Apple Configuration Profile With SCEP Certificates For SimpleMDM

Prerequisites for Configuring Apple Configurator with SCEP

  1. You will need an EZCA SCEP CA set up and ready to issue certificates.

How to Download An Apple Configuration Profile from your EZCA SCEP CA

  1. Navigate to your EZCA portal and sign in as a PKI administrator.

  2. Click on the Certificate Authorities tab and scroll to your SCEP CA.

  3. Click on the View Requirements button for your SCEP CA.

    View Certificate Authorities in EZCA Cloud PKI
  4. Scroll down to the Apple Configuration Profile section and click Download Apple Configuration Profile.

    How to Download An Apple Configuration Profile from your EZCA Cloud PKI SCEP CA with the Download Apple Configuration Profile button highlighted
  5. Done!

Prerequisites for Configuring iMazing Profile Editor with SCEP

  1. You will need a macOS device with Apple Configurator installed to create the custom profile.
  2. You will need an EZCA SCEP CA set up and ready to issue certificates.

How to Download Your Root and/or SCEP CA Certificates from EZCA

To establish trust for your SCEP certificates, you will need to download and later push the CA certificate(s) for your SCEP CA to your devices. If your SCEP CA is a subordinate CA, you will need to download both the root and SCEP CA certificates. If your SCEP CA is a root CA, you will only need to download the SCEP CA certificate.

  1. Navigate to your EZCA portal and sign in as a PKI Administrator.

  2. Click on the Certificate Authorities tab and scroll to your SCEP CA.

  3. Click on the View Requirements button for your SCEP CA.

    View Certificate Authorities in EZCA on macOS
  4. Scroll down to the CA Locations section and click on the Download Certificate button for your CA.

    Download Root Certificate in EZCA on macOS

How to Enable Static SCEP Challenge in Your EZCA SCEP CA

Before you can create a custom profile for SCEP in Apple Configurator, you need to ensure that your EZCA SCEP CA is configured to use a static challenge.

  1. Navigate to your EZCA portal and sign in as a PKI Administrator.

  2. Click on the Certificate Authorities tab and scroll to your SCEP CA.

    Certificate Authorities in EZCA Portal
  3. Click on View Requirements for your SCEP CA.

  4. Check the box for Enable SCEP Static Challenge and click Save Changes. You will now see your Static Challenge SCEP URL and SCEP Challenge:

    SCEP CA Static Challenge in EZCA Portal

How to Create a Configuration Profile in Apple Configurator for SCEP

  1. Start on a macOS device with Apple Configurator installed.

  2. Open Apple Configurator, and click on FileNew Profile to create a new configuration profile.

  3. Fill out the General section with a name, identifier, and description for the profile.

    Apple Configurator General Section for SCEP Profile
  4. Click on the Certificates section and then click on the Configure button to add a new certificate payload.

  5. Select the CA certificate you downloaded from EZCA and upload it to the profile. This will ensure that the CA certificates are pushed to the devices and that they trust the SCEP CA.

  6. Repeat the process to upload the root CA certificate if your SCEP CA is a subordinate CA.

    Apple Configurator Certificates Section for SCEP Profile
  7. Next, click on the SCEP section and click on the Configure button to add a new SCEP payload.

  8. Copy the Static Challenge SCEP URL from your EZCA portal and paste it into the URL field in Apple Configurator. Do the same for the Static Challenge in the Challenge field.

  9. Configure the remaining fields:

    • Name: Set as the name of your SCEP CA
    • Subject: Use a static value or Apple’s built-in variables (e.g. CN=%HardwareUUID%)
    • Subject Alternative Name Type: Set as DNS Name
    • Subject Alternative Name Value: Use a static value or Apple’s built-in variables (e.g. %HostName%)
    • Key Size: Set as 2048 or higher.
    • Key Usage: Set as “Sign” and “Key Encipherment”.
  10. You should now have a complete SCEP configuration in your custom profile:

    Apple Configurator SCEP Section for SCEP Profile
  11. Save the profile to your device as a .mobileconfig file.

Prerequisites for Configuring iMazing Profile Editor with SCEP

  1. You will need a macOS or Windows device with iMazing Profile Editor installed to create the custom profile.
  2. You will need an EZCA SCEP CA set up and ready to issue certificates.

How to Download Your Root and/or SCEP CA Certificates from EZCA

To establish trust for your SCEP certificates, you will need to download and later push the CA certificate(s) for your SCEP CA to your devices. If your SCEP CA is a subordinate CA, you will need to download both the root and SCEP CA certificates. If your SCEP CA is a root CA, you will only need to download the SCEP CA certificate.

  1. Navigate to your EZCA portal and sign in as a PKI Administrator.

  2. Click on the Certificate Authorities tab and scroll to your SCEP CA.

  3. Click on the View Requirements button for your SCEP CA.

    View Certificate Authorities in EZCA on macOS
  4. Scroll down to the CA Locations section and click on the Download Certificate button for your CA.

    Download Root Certificate in EZCA on macOS

How to Enable Static SCEP Challenge in Your EZCA SCEP CA

Before you can create a custom profile for SCEP in iMazing Profile Editor, you need to ensure that your EZCA SCEP CA is configured to use a static challenge.

  1. Navigate to your EZCA portal and sign in as a PKI Administrator.

  2. Click on the Certificate Authorities tab and scroll to your SCEP CA.

    Certificate Authorities in EZCA Portal
  3. Click on View Requirements for your SCEP CA.

  4. Check the box for Enable SCEP Static Challenge and click Save Changes. You will now see your Static Challenge SCEP URL and SCEP Challenge:

    SCEP CA Static Challenge in EZCA Portal

How to Create a Configuration Profile in iMazing Profile Editor for SCEP

  1. Download and install iMazing Profile Editor.

  2. Open iMazing Profile Editor, and click on FileNew Profile to create a new configuration profile.

  3. Fill out the General section with a name and description for the profile.

  4. Click on the Root Certificate section and then click on the Add Payload button to add a new certificate payload.

    iMazing Profile Editor Certificates Section for SCEP Profile
  5. Select the Root CA certificate you downloaded from EZCA and upload it to the profile. This will ensure that the Root CA certificates are pushed to the devices and that they trust the SCEP Root CA.

  6. Repeat the process to upload the CA certificate if your SCEP CA is a subordinate CA.

    iMazing Profile Editor Certificates Section Add Payload for SCEP Profile
  7. Next, click on the SCEP section and click on the Add Payload button to add a new SCEP payload.

    iMazing Profile Editor Certificates Section Add Payload for SCEP Profile
  8. Copy the Static Challenge SCEP URL from your EZCA portal and paste it into the URL field in iMazing Profile Editor.

    iMazing Profile Editor Certificates Section Add Payload for SCEP Profile
  9. Copy the Challenge from EZCA and paste it into the Challenge field.

  10. Configure the remaining fields:

    • Subject: Use a static value or Apple’s built-in variables (e.g. CN=%HardwareUUID%)

    • Retries: 3

    • Retry Delay: 30

    • Key Size: Set as 2048 or higher.

    • Key Usage: Set as Both signing and encryption.

      iMazing Profile Editor Certificates Section for SCEP Profile
  11. You should now have a complete SCEP configuration in your custom profile:

  12. Click FileSave to save the profile to your device as a .mobileconfig file.

How To Issue SCEP Certificates to SimpleMDM Devices for RADIUS Authentication

Once you have created your .mobileconfig file, you will need to issue it to all your devices.

  1. Open SimpleMDM in your browser.

  2. Navigate to ConfigProfiles.

  3. Click Create Profile.

    Create new Profile SimpleMDM
  4. Select Custom Configuration Profile.

    Select Custom Configuration Profile
  5. Name your profile.

  6. Disable Install via Declarative Management.

    Disable Declarative Management
  7. Upload the .mobileconfig you just created.

  8. Enable Auto renew SCEP issued certificates.

    Enable Auto Renew SCEP Certificates
  9. Scroll to the bottom and click Save.

  10. Click on the profile you just created.

  11. Click on the Groups tab.

    Navigate to Groups Tab
  12. Click Assign Group.

    Assign Profile to Group
  13. Select all the groups you want to assign this profile to.

    Select Groups for Profile
  14. Click Assign.

  15. Navigate to DevicesGroups.

  16. Select the group you assigned the profile to.

    Select Profile Group
  17. Click on Group Actions and select Sync Profiles.

    Sync Profiles
  18. Repeat for any additional groups.

  19. Done!

Enjoying EZCA? Leave Us a Review!

We hope you’re enjoying using EZCA to issue your SCEP certificates! If you have a moment, we would greatly appreciate it if you could leave us a review on G2. Your feedback helps other IT professionals discover EZCA and helps us continue to improve our service. Thank you for your support!