Setting Up SCEP Parent topic

Note
Note
This topic applies to Full Version deployment mode only.
Setting up Simple Certificate Enrollment Protocol (SCEP) provides additional security for iOS mobile devices.

Procedure

  1. Install Certificate Authority
    For the detailed Certificate Authority installation procedure, refer to the following URL:
    Note
    Note
    If you do not want to use SCEP, you do not need to install the Certificate Authority.
  2. Configure Simple Certificate Enrollment Protocol (SCEP)
    If you have set up SCEP on Windows Server 2008, install the Network Device Enrollment Service for Windows Server. Refer to the following URL for the installation and deployment procedure of Network Device Enrollment Service:
    or
    Note
    Note
    If you want to use SCEP, Trend Micro recommends using it on Windows Server 2008.
  3. Verify system clocks
    Make sure that the system clocks of SCEP server, Communication Server and the Management Server are set to the correct time.
  4. Modify Policy Module properties for Certificate Authority:
    1. On the computer where Certificate Authority is installed, open the Certification Authority management console.
    2. Click Policy Module tab, and then click Properties.
    3. Select Follow the settings in the certificate template, if applicable. Otherwise, automatically issue the certificate.
    4. Click OK.
  5. Apply the following set of rules:
    • iOS mobile devices should be able to connect to the Communication Server.
    • Communication Server should be able to connect to the SCEP server.
    • iOS mobile devices should be able to directly connect to the SCEP server when enrolling to the Mobile Security Management Server.
  6. Verify the SCEP installation (Optional):
    For SCEP running on Windows Server 2008, access the following URL from the Communication Server:
    Note
    Note
    Replace SCEPServerIP with the actual SCEP server IP address in the URL.
    If you see the Web page similar to the following, your server is configured correctly:
    NDES_Verification-3.png

    Configuration Verification

    Note
    Note
    When iOS mobile device enrolls, it will be able to access the following URL:
    The iOS mobile device only needs to connect to the SCEP ` for enrollment, and does not require this connection for any further use.