SCEP
Simple Certificate Enrollment Protocol — how it works and where it fits
SCEP (originally defined by Cisco, now RFC 8894) is the most widely supported certificate enrollment protocol in network equipment. It uses a challenge-password model over HTTP, making it deployable on devices that cannot support ACME or EST.
How it works
- An administrator generates a one-time challenge password in the Horizon WebRA or via the API.
- The device sends a PKCS#10 CSR and the challenge password to the Horizon SCEP endpoint.
- Horizon validates the password, issues the certificate, and returns it in a PKCS#7 envelope.
- For renewal, the device re-enrolls using its existing certificate as proof of identity, if the profile permits.
Where SCEP fits
- Network devices — Cisco IOS, Fortinet FortiGate, Palo Alto PAN-OS, Juniper Junos, and most other network operating systems support SCEP. It is the most reliable choice for gear that does not speak EST or ACME.
- MDM platforms — Microsoft Intune and Jamf Pro have dedicated Horizon integrations that use SCEP to request certificates on behalf of managed devices. See MDM integrations below.
- Legacy environments — any system where ACME or EST cannot be deployed and where the challenge-password model is acceptable.
- VPN gateways and firewalls — for device-identity certificates used in IPsec or SSL VPN configurations.
Where a device supports both EST and SCEP, prefer EST. EST renewal uses mutual TLS rather than a shared password, and does not require administrator action to generate a new challenge for each device.
Where SCEP does not fit well
- High-volume server automation — the challenge-password model requires per-device administrative action at initial enrollment. The Horizon Agent handles this automatically for servers. Use the Agent instead.
- Short-validity certificates without scripting — if certificates need to be renewed frequently (below 90 days), the manual challenge step does not scale unless the renewal flow is scripted end-to-end.
MDM integrations
Horizon has dedicated integration profiles for Microsoft Intune and Jamf Pro — these are not simply MDM platforms pointing at a SCEP URL. Each has its own connector, scheduled tasks, and device lifecycle features in Horizon.
Microsoft Intune
Horizon offers two distinct Intune integration modes:
- SCEP mode — Intune requests certificates via SCEP on behalf of enrolled devices. Horizon validates the request against the Intune connector and issues the certificate. When a device is decommissioned in Intune, Horizon automatically revokes its certificate using the
AAD_Device_IDstored in the subject DN. - PKCS mode — Horizon issues certificates via its REST API through the Microsoft Certificate Connector, bypassing SCEP entirely. This mode does not require a SCEP Authority and is the simpler path for environments already using the Microsoft Certificate Connector.
When configuring the SCEP server URL in Intune for Windows machine or user certificates, remove the trailing pkiclient.exe from the URL that Horizon provides.
Jamf Pro
Horizon integrates with Jamf Pro for both iOS and macOS device certificates. When a device is decommissioned in Jamf, Horizon automatically revokes its certificate using the device UDID stored in the subject DN.
Jamf supports four integration modes:
- SCEP Proxy — Jamf acts as a proxy between the device and Horizon's SCEP endpoint.
- iOS SCEP Profile — direct SCEP enrollment for iOS devices (RA mode).
- macOS SCEP Profile — direct SCEP enrollment for macOS devices (CA mode).
- macOS SCEP Profile with Proxy — macOS enrollment via Jamf's SCEP proxy.
On the Jamf Pro side, the challenge type must be set to Dynamic-Microsoft CA and the SCEP URL pointed at the corresponding Horizon endpoint.
SCEP Authority prerequisite
Both Intune and Jamf integrations require a dedicated SCEP Authority certificate — a certificate issued by the same CA as the endpoint certificates, with Digital Signature and Key Encipherment key usages, imported into Horizon as a PKCS#12. This is a prerequisite for setting up either integration and must be prepared before configuring the profile.
Security considerations
SCEP was designed before modern TLS was ubiquitous. Horizon enforces HTTPS for all SCEP endpoints. One-time challenge passwords are single-use and short-lived, but they should still be treated as secrets and delivered to devices out of band — not embedded in configuration management templates in plain text.
Configuring SCEP in Horizon
SCEP is enabled per-profile. Challenge passwords are generated in the WebRA under Request → SCEP Challenge.
Refer to the Horizon WebRA SCEP documentation and the Horizon Client SCEP documentation for setup details.