Administrator Guide

Table Of Contents
Simplified Certificate Enrollment Protocol
Simplified Certificate Enrollment Protocol (SCEP) was designed to be used in a closed network where all end-points are trusted.
The goal of SCEP is to support the secure issuance of certificates to network devices in a scalable manner. Within an enterprise
domain, it enables network devices that do not run with domain credentials to enroll for certificates from a Certification
Authority (CA).
At the end of the transactions defined in this protocol, the network device has a private key and associated certificate that is
issued by a CA. Applications on the device may use the key and its associated certificate to interact with other entities on the
network. The most common usage of this certificate on a network device is to authenticate the device in an IPSec session.
ThinOS is treated as a network device. The functionality of ThinOS SCEP include manual certificate request, automatic
certificate request, and automatic renewal of certificate.
Requesting certificate manually
To request the certificate manually, do the following:
1. Go to System Tools > Certificates > Request Certificate.
The Request Certificate dialog box is displayed.
2. Enter the appropriate values in the Request Certificate dialog box, and then click the Request Certificate button.
The certificate request is sent to the server, and the client receives the response from server and installs both CA certificate
and client certificate.
138
Performing diagnostics