Set up SCEPman
SCEPman is a SCEP certificate service that runs as an Azure App Service in your own tenant, with its CA keys held in Azure Key Vault. It can issue the device identity certificates Firezone validates.
Before you begin
You need a deployed SCEPman instance and permission to edit its App Service configuration. See SCEPman's deployment guides if you do not have one yet.
1. Create the root CA
Browse to the SCEPman app in App Services, confirm its status indicators are green, and create the Azure Key Vault root CA certificate with Create First Node. Create the root only once per farm. See Root CA for the full first-run sequence, and Intermediate CA if your deployment uses one.
2. Choose a SCEP endpoint
SCEPman validates enrollment requests differently depending on which system sends them, and each mode listens on its own endpoint.
| Your provisioning system | SCEPman mode |
|---|---|
| Microsoft Intune | Intune validation |
| Jamf Pro | Jamf validation |
| Iru, or any other MDM | Static validation |
To enable the static endpoint, set these App Service configuration values:
| Setting | Value |
|---|---|
AppConfig:StaticValidation:Enabled | true |
AppConfig:StaticValidation:RequestPassword | A 32 character shared secret, used as the SCEP challenge |
AppConfig:StaticValidation:ValidityPeriodDays | Optional. Certificate lifetime for this endpoint |
Restart the App Service after changing configuration. Store the request
password as a secret in Azure Key Vault, named
AppConfig--StaticValidation--RequestPassword, rather than inline.
The static endpoint is served at /static, so the SCEP URL you give your MDM
is your SCEPman hostname followed by that path, for example
https://scepman.example.com/static.
3. Check the certificate defaults
By default AppConfig:UseRequestedKeyUsages is false, which means SCEPman
sets the key usages itself: Extended Key Usage is always Client
Authentication, and Key Usage is always Key Encipherment and Digital
Signature. Those are the values Firezone requires, so the default needs no
change.
If your deployment sets AppConfig:UseRequestedKeyUsages to true, the MDM
profile becomes responsible for requesting Client Authentication itself, and
the profile must do so or Firezone will reject the certificate.
AppConfig:ValidityPeriodDays caps certificate lifetime at 730 days by
default. See
Certificates
for the full list of settings.
4. Configure your MDM's SCEP profile
Point the profile at the SCEP URL and challenge from step 2, then set the subject and SANs that Firezone needs:
- Subject common name fixed at
CN=dev.firezone.device-trust. - A supported
device identifier as a URI
SAN, such as
firezone://serial/C02ABC123.
The provider guides for Intune, Iru and Jamf Pro give the profile fields and the variable syntax each one uses to populate the device identifier.
Inspect an issued certificate before deploying broadly, and confirm it carries both the fixed common name and the URI SAN with a real device value. A profile can look correct while the CA rewrites the subject or drops the requested SANs.
5. Collect the CA certificates
Download the root CA certificate, and the intermediate if your deployment has one, from the SCEPman web interface. These are the files you add to Firezone.
Revocation is optional but supported: see Enabling CRL and OCSP if you want revocation to take effect.
Next step
Add the root and intermediate public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.
Need help? See all support options.