Back to Demos
37/52
EnterpriseIntermediate
SCEP Protocol
Learn Simple Certificate Enrollment Protocol for automated device certificate provisioning.
Interactive Demo

Device
SCEP Server
Certificate Authority
Step 1 of 5GetCACaps
In ProgressWhat capabilities do you support?
Device discovers supported algorithms, hash functions, and enrollment options.
Challenge Password Authentication
Admin generates challenge password in SCEP server
Password given to device (manually or via MDM)
Device includes password in PKCSReq
Server validates before issuing certificate
This prevents unauthorized devices from obtaining certificates
Want to learn more?
Read our comprehensive guide on SCEP and device certificate enrollment