- Download Client CA from the SCEP page by clicking 'Download CA' button under Client Certificate Authorities. Change the extension of the downloaded CA certificate file from .crt to .cer.
- Download active Server CA from the SCEP page by clicking 'Download CA' under 'Server Certificate Authorities'.
- Download Apple Configurator Application
- Click on SCEP in left menu
- URL - Obtain the URL from SCEP page. It will be mentioned below 'Unique Endpoint' heading on the SCEP page. Please see the screenshot below for reference. Copy the endpoint from Foxpass console and paste it under URL in Apple Configurator.
- Name - leave blank
- Subject - CN=<user's email address>
- Subject Alternative Name Value (optional) - RFC822: <user's email address>.
- Challenge - Copy the Challenge password from the SCEP page.
- Fingerprint - Click 'Create from Certificate' and select the CA certificate you downloaded earlier.
- Go back to Apple Configurator 2. Click Certificates on the left side of your profile.
- Click Configure. Select 'Server CA' (The one you downloaded in Step 2)from the 'Downloads' folder. You will start seeing 'Server CA' as specified in the screenshot below:
- By default, enterprise settings are selected to Protocols.
- SSID - Your network's SSID Note: this must match EXACTLY, including capital letters.
- Security Type - WPA/WPA 2 Enterprise
- Protocols - TLS
- Identity Certificate - Select SCEP from the dropdown.
- Now select 'Trust' in 'Enterprise Settings'. Select the Server CA.
Go to your MAC System Settings, search Profiles > Install, view or remove configuration profiles. Click on the the profile you just configured in Apple Configurator 2. A dialog box will open to ask if you want to install the profile. Click 'Install'.Save and test
The profile will be installed and you can see a SCEP certificate under 'Client Certificates' on the SCEP page.
If there are any SCEP errors, it will be displayed as an alert in red colored box on the top of the SCEP page of the Foxpass console.
Updated 17 days ago