WSTEP / WCCE
Windows-native certificate enrollment — how it works and where it fits
WSTEP (WS-Trust Enrollment Protocol) and MS-WCCE (Microsoft Windows Client Certificate Enrollment Protocol) are the protocols built into Windows for certificate enrollment. Active Directory domain members use these protocols to enroll machine and user certificates via Group Policy auto-enrollment and the Certificate MMC snap-in. Horizon supports both through WinHorizon, a dedicated proxy component that sits between Windows clients and Horizon, presenting the same interface that Windows expects from ADCS.
How it works
- A Windows machine or user contacts the enrollment endpoint specified in Active Directory or Group Policy.
- Authentication is via Kerberos — the machine or user's AD identity is the credential; no separate password or challenge is needed.
- WinHorizon receives the request, maps the certificate template name to a Horizon profile, and forwards it to Horizon.
- Horizon issues the certificate and returns it through WinHorizon to the client.
- The certificate is installed automatically into the Windows Certificate Store.
- Auto-enrollment handles renewal transparently — Windows re-enrolls before expiry with no user interaction.
Required components
WCCE/WSTEP requires WinHorizon — a separate EverTrust component that must be deployed as a proxy in your environment. Windows clients do not connect directly to Horizon. WinHorizon handles the WCCE/WSTEP protocol translation and forwards requests to Horizon over its REST API.
Before creating WCCE profiles, a WCCE Forest must be configured in Horizon to represent the Active Directory forest. This is a prerequisite for all subsequent profile and template mapping configuration.
Each WCCE profile also requires a dedicated Exchange Certificate (configured with key escrow) that WinHorizon uses to secure the enrollment exchange.
Template mapping
Windows clients request certificates by template name (for example, WebServer or ComputerCertificate). Horizon does not use certificate templates natively; instead, a template mapping must be configured for each WCCE profile to translate the Windows template name to the corresponding Horizon profile. This mapping is a required configuration step separate from creating the profile itself.
Where WSTEP / WCCE fits
- Domain-joined Windows machines — the native enrollment path, driven entirely by Group Policy and the Windows Certificate Store.
- Windows user certificates — email signing, smartcard logon, VPN client authentication.
- Replacing ADCS — WinHorizon presents the same WCCE/WSTEP interface Windows expects. Group Policy requires no change beyond updating the enrollment endpoint URL to point at WinHorizon instead of the ADCS CA.
- Organisations with mature AD infrastructure — AD group membership can drive which profiles a machine or user can enroll against, using the same group-based access model as ADCS certificate templates.
Where WSTEP / WCCE does not fit
- Non-Windows endpoints — Linux, macOS, and network devices do not support these protocols. Use the Horizon Agent (EST), ACME, or SCEP for those systems.
- Workloads outside Active Directory — Kerberos authentication requires AD domain membership. Use another protocol for standalone Windows machines, workgroup servers, or cloud-only environments.
Compared to the ADCS Connector
The ADCS Connector connects Horizon to an existing ADCS CA so that Horizon can issue certificates through it. WSTEP/WCCE is the enrollment protocol that Windows clients use to talk to WinHorizon (and through it, to Horizon) — these are complementary, not alternatives.
Configuring WSTEP / WCCE in Horizon
Configuration order: deploy WinHorizon → configure a WCCE Forest → create a WCCE Profile → configure template mappings → update the enrollment URL in Group Policy.
Refer to the Horizon WCCE documentation and the WinHorizon installation guide for setup steps.