SCEP with Jamf Pro - IronWiFi PKI - Device Auth

SCEP with Jamf Pro - IronWiFi PKI - Device Auth

The Simple Certificate Enrollment Protocol (SCEP) is a protocol that allows devices to easily enroll for a certificate by using a URL and a shared secret to communicate with a PKI.

This is a guide for setting up SCEP with IronWiFi's new multi-tiered HSM based Certificate Authority and Jamf Pro to provision MacOS and iOS / iPadOS  based devices, using device profile.

What do you need ?

  • owner_id - owner id is a unique identifier of your IronWiFi account that can be found in the URL when you're logged in, it should look similar to this - abcdefg12345678 or domain-abcd1234
  • region - region where your data resides and authentication requests are processed - us-east1, console, asia-northeast1, etc
  • SCEP Server URL - build the URL in this format - https://{{region}}.ironwifi.com/api/{{owner_id}}/certificates/scep

  • Template file for Apple Configurator 2. The file can be downloaded from here

!Note! Your user must exist in the IronWiFi console or the SCEP connector's User Auto-Creation option must be enabled for this to work. We are mapping  device serial number to the username in console

 

1. Sign in to the IronWiFi Management Console and create a SCEP connector - click on Users -> Connectors -> New Connector

Screenshot 2023-03-23 12.00.18 PMScreenshot 2023-03-23 12.00.46 PM

2. Open IronWiFi SCEP Device.mobileconfig that you have downloaded in Apple Configurator 2

3. Click on General and modify Name and  Organisation.


4. Click on Wi-Fi and modify SSID to match your own SSID that you are broadcasting.

5. Click on SCEP and replace {{region}} and {{owner_id}} placeholders with your own region and owner_id from the console URL.

For example if your console URL is https://europe-west3.ironwifi.io/api/index?#/i-03297e33/ , the region will be europe-west3 and owner_id will be i-03297e33 and the resulting SCEP URL would be: https://europe-west3.ironwifi.com/api/i-03297e33/certificates/scep
Do the same for Subject.


6. Save the mobileconfig file - Command + S

7. Log in to your Jamf Pro account, go to Devices -> Configuration Profiles and Upload the .mobileconfig file. Assign the created profile to your devices or device groups as required.



    • Related Articles

    • SCEP with Intune - IronWiFi PKI - Device Auth

      The Simple Certificate Enrollment Protocol (SCEP) is a protocol that allows devices to easily enroll for a certificate by using a URL and a shared secret to communicate with a PKI. This is a guide for setting up SCEP with IronWiFi's new multi-tiered ...
    • SCEP with Intune - IronWiFi PKI - User Auth

      The Simple Certificate Enrollment Protocol (SCEP) is a protocol that allows devices to easily enroll for a certificate by using a URL and a shared secret to communicate with a PKI. This is a guide for setting up SCEP with IronWiFi's new multi-tiered ...
    • IronWiFi PKI Infrastructure

      The old Root CA certificate has expired on May 18, 2024. You can download the new certificates below. Hardware-Backed Security IronWiFi PKI infrastructure employs the latest industry standards for the private key protection, relying on the HSM ...
    • Implementing Private PKI with IronWiFi

      Thanks to our modular PKI infrastructure we are able to offer the Private PKI for our most demanding customers. Whilst security level of our standard offering leaves nothing to be desired, we are able to offer two additional solutions for our ...
    • Implementing Private PKI with IronWiFi

      Thanks to our modular PKI infrastructure we are able to offer the Private PKI for our most demanding customers. Whilst security level of our standard offering leaves nothing to be desired, we are able to offer two additional solutions for our ...