Guides
Certificates, SCEP and 802.1X, explained properly.
Background on the protocols and the deployment decisions behind putting a certificate on every device. Written for the person who has to make it work, not to sell you something — the documentation covers what ScepNet itself does.
What is a SCEP server?
The enrollment exchange step by step, what challenge passwords really protect, and the trade-off between running your own SCEP server and using a hosted one.
802.1X certificate authentication
EAP-TLS versus PEAP, what your RADIUS server needs, the SAN and UPN details that break deployments, and the order to roll it out in.
An alternative to NDES
What NDES does, why it is awkward to run and expose, and how to replace it while keeping your existing root CA and avoiding an outage.
Tools
Or just try it.
Five devices free, permanently — no card and no expiry date. Your own certificate authority and a SCEP endpoint your MDM can point at this afternoon.
- Your own root and intermediate CA
- Standard SCEP — any MDM, no agent
- Nothing of yours exposed to the internet