Create a SCEP profile
The required profile settings depend on the SCEP service configuration in your organization's environment and vary depending on whether the certificate is used by a
BlackBerry
Dynamics
app or by a specified device type.You can use a variable in any text field to reference a value instead of specifying the actual value.
If you want to use a SCEP profile to distribute
OpenTrust
client certificates to devices, you must apply a hotfix to your OpenTrust
software. For more information, contact your OpenTrust
support representative and reference support case SUPPORT-798.- On the menu bar, clickPolicies and profiles > Certificates > SCEP.
- Click .
- Type a name and description for the profile.
- In theCertificate authority connectiondrop-down list, perform one of the following actions:
- To use anEntrustconnection that you configured, click the appropriate connection. In theProfiledrop-down list, click a profile. Specify the values for the profile.
- To use anOpenTrustconnection that you configured, click the appropriate connection. In theProfiledrop-down list, click a profile. Specify the values for the profile. Note that the following settings in the SCEP profile do not apply toOpenTrustclient certificates: Key usage, Extended key usage, Subject, and SAN.
- To use another CA, clickGeneric. In theSCEP challenge typedrop-down list, selectStaticorDynamicand specify the required settings for the challenge type.ForWindowsdevices, only static passwords are supported.
- In theURLfield, type the URL for the SCEP service. The URL should include the protocol, FQDN, port number, and SCEP path.
- In theInstance namefield, type the instance name for the CA.
- Optionally, clear the check box for any device type that you do not want to configure the profile for.
- Perform the following actions:
- Click the tab for a device type.
- Configure the appropriate values for each profile setting to match the SCEP service configuration in your organization's environment. See the following:
- Repeat step 8 for each device type in your organization.
- ClickAdd.
If devices use the client certificate to authenticate with a work
Wi-Fi
network, work VPN, or work mail server, associate the SCEP profile with a Wi-Fi
, VPN, or email profile.