Administrator Guide

Table Of Contents
Simplified Certificate Enrollment ProtocolSCEP
Simplified Certificate Enrollment Protocol (SCEP) was designed to be used in a closed network where all end-points are trusted.
The goal of SCEP is to support the secure issuance of certificates to network devices in a scalable manner. Within an enterprise
domain, it enables network devices that do not run with domain credentials to enroll for certificates from a Certification
Authority (CA).
At the end of the transactions defined in this protocol, the network device will have a private key and associated certificate that
is issued by a CA. Applications on the device may use the key and its associated certificate to interact with other entities on the
network. The most common usage of this certificate on a network device is to authenticate the device in an IPSec session.
ThinOS Lite is treated as a network device. The functionalities of ThinOS Lite SCEP include manual certificate request,
automatic certificate request, and automatic renewal of certificate.
Requesting certificate manually
To request the certificate manually, do the following:
1. Go to System Tools > Certificates > Request Certificate.
The Request Certificate dialog box is displayed.
Figure 132. Request Certificate
2. Enter the appropriate values in the Request Certificate dialog box, and then click the Request Certificate button.
The certificate request is sent to the server and the client receives the response from server and installs both CA certificate
and client certificate.
140
Performing Diagnostics