Create a SCEP profile
The required profile settings depend on the SCEP service configuration in your organization's environment and vary depending on whether the certificate is used by a BlackBerry Dynamics app or by a specified device type.
You can use a variable in any text field to reference a value instead of specifying the actual value.
- On the menu bar, click Policies and profiles > Certificates > SCEP.
- Click
.
- Type a name and description for the profile.
- In the Certificate authority connection drop-down list, perform one of the following actions:
- To use an Entrust connection that you configured, click the appropriate connection. In the Profile drop-down list, click a profile. Specify the values for the profile.
- To use an OpenTrust connection that you configured, click the appropriate connection. In the Profile drop-down list, click a profile. Specify the values for the profile. Note that the following settings in the SCEP profile do not apply to OpenTrust client certificates: Key usage, Extended key usage, Subject, and SAN.
- To use another CA, click Generic. In the SCEP challenge type drop-down list, select Static or Dynamic and specify the required settings for the challenge type. For Windows devices, only static passwords are supported.
- In the URL field, type the URL for the SCEP service. The URL should include the protocol, FQDN, port number, and SCEP path.
- In the Instance name field, type the instance name for the CA.
- Optionally, clear the check box for any device type that you do not want to configure the profile for.
- Perform the following actions:
- Repeat step 8 for each device type in your organization.
- Click Add.