<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sinking Our Teeth Into SCEP</title>
	<atom:link href="http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/</link>
	<description>place of the mobility way</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:15:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/comment-page-1/#comment-13719</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Fri, 25 Jun 2010 10:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=951#comment-13719</guid>
		<description>I do not know if renewing certificates is dependent on GetCACaps since this operation is just about providing info on what the CA supports. So, I do not know if it could be an issue with the templates, or something else security-related.

Service Pack 1 for 2008 R2 is due in a couple of months, but I have not seen anything in the info regarding this service pack that there will be any updates to the CA role or anything pertaining to NDES/SCEP. It is due in a public beta before the end of July so we&#039;ll just have to take a closer look then. If it&#039;s not added in that release it&#039;s anybody&#039;s guess if/when it will be added. (A new major CA release would probably be a bit into the future.)</description>
		<content:encoded><![CDATA[<p>I do not know if renewing certificates is dependent on GetCACaps since this operation is just about providing info on what the CA supports. So, I do not know if it could be an issue with the templates, or something else security-related.</p>
<p>Service Pack 1 for 2008 R2 is due in a couple of months, but I have not seen anything in the info regarding this service pack that there will be any updates to the CA role or anything pertaining to NDES/SCEP. It is due in a public beta before the end of July so we&#8217;ll just have to take a closer look then. If it&#8217;s not added in that release it&#8217;s anybody&#8217;s guess if/when it will be added. (A new major CA release would probably be a bit into the future.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Buck</title>
		<link>http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/comment-page-1/#comment-13585</link>
		<dc:creator>Stephen Buck</dc:creator>
		<pubDate>Wed, 23 Jun 2010 23:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=951#comment-13585</guid>
		<description>I&#039;m having a problem with our Cisco devices auto-renewing their certificates.  It seems that since the GetCACaps operation is not supported by Microsoft&#039;s NDES, the devices can&#039;t automatically renew their certs and so generate a new request for a new cert.

Have you heard if Microsoft is going to support the GetCACaps operation to allow devices to renew their certs?</description>
		<content:encoded><![CDATA[<p>I&#8217;m having a problem with our Cisco devices auto-renewing their certificates.  It seems that since the GetCACaps operation is not supported by Microsoft&#8217;s NDES, the devices can&#8217;t automatically renew their certs and so generate a new request for a new cert.</p>
<p>Have you heard if Microsoft is going to support the GetCACaps operation to allow devices to renew their certs?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/comment-page-1/#comment-9903</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 25 Mar 2010 23:20:48 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=951#comment-9903</guid>
		<description>And I thought Apple was all about being helpful :)

Jokes aside; tThe first operation, GetCACert, is ok. The second, GetCACaps, is not supported on MS CA (as far as I can tell), so that&#039;s ok too since it&#039;s optional anyways. The third, PKIOperation, which just happens to be the tricky one to get right fails. You get a statuscode 200 because the request was POSTed successfully to the SCEP server, and possibly processed by the CA too. But it most likely failed because the request wasn&#039;t properly built or something.

You should check the event viewer on the CA - it might provide an error message as to what was wrong with the request - could be missing/incorrect attributes, missing key material, etc.

Are you letting the iPhone do the actual enrollment, or is there a component server side that is trying to request certificates and provision the result to the iPhones?</description>
		<content:encoded><![CDATA[<p>And I thought Apple was all about being helpful <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Jokes aside; tThe first operation, GetCACert, is ok. The second, GetCACaps, is not supported on MS CA (as far as I can tell), so that&#8217;s ok too since it&#8217;s optional anyways. The third, PKIOperation, which just happens to be the tricky one to get right fails. You get a statuscode 200 because the request was POSTed successfully to the SCEP server, and possibly processed by the CA too. But it most likely failed because the request wasn&#8217;t properly built or something.</p>
<p>You should check the event viewer on the CA &#8211; it might provide an error message as to what was wrong with the request &#8211; could be missing/incorrect attributes, missing key material, etc.</p>
<p>Are you letting the iPhone do the actual enrollment, or is there a component server side that is trying to request certificates and provision the result to the iPhones?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://mobilitydojo.net/2010/01/20/sinking-our-teeth-into-scep/comment-page-1/#comment-9895</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Thu, 25 Mar 2010 20:27:40 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=951#comment-9895</guid>
		<description>Hello,

Thanks for posting this excellent note on SCEP. We are working on using MS SCEP to provision an iPhone and are running into some issues. We are not getting any help from Apple. The following is a description of our problem. 

I&#039;m using Windows Server 2008 Enterprise with the Microsoft SCEP implementation (NDES) installed and configured.  I can verify that a client computer receives a certificate back, but on the iPhone I can only validate that it&#039;s failing because it doesn&#039;t tell me anything other than it failed to install.  Through using a packet sniffer, I can validate the following HTTP conversation between the CA/SCEP server and the iPhone.

The iPhone is sending an HTTP GET command with the URI:
Location:       /certsrv/mscep/
Operation:      GetCACert
Message:        hostname

The response from the CA/SCEP machine is StatusCode of 200 with a payload of type &#039;application/x-x509-ca-ra-cert&#039;, which I have validated through using another host where I can examine the file that it is a p7b file which is a PKCS #7 file.

The iPhone next issues another GET command, with the URI:
Location:       /certsrv/mscep/
Operation:      GetCACaps
Message:        hostname

The response from the CA/SCEP machine is StatusCode of 200 with a 0 length content.

The iPhone next issues another GET command, with the URI:
Location:       /certsrv/mscep/
Operation:      PKIOperation
Message:        message: MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAaCAJIAEggNnMIAG%0ACSqGSIb3DQEHA6CAMIACAQAxggF9MIIBeQIBADBhMFMxEzARBgoJkiaJk%2FIsZAEZFgNsYWIxFzAV%0ABgoJkiaJk%2FIsZAEZFgdtYXR0bGFiMSMwIQYDVQQDExptYXR0bGFiLU1BVFRMQUJWTTY0MjAwOC1D%0AQQIKYQrpd

To which the CA/SCEP machine responds with StatusCode 200 with a payload of type &#039;application/x-pki-message.&#039;  The contents of the payload are included as an attachment.  So, ultimately, it appears that the iPhone doesn&#039;t like the contents of the application/x-pki-message.

Any thoughts on what could be wrong?

Your help much appreciated.

Jay</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Thanks for posting this excellent note on SCEP. We are working on using MS SCEP to provision an iPhone and are running into some issues. We are not getting any help from Apple. The following is a description of our problem. </p>
<p>I&#8217;m using Windows Server 2008 Enterprise with the Microsoft SCEP implementation (NDES) installed and configured.  I can verify that a client computer receives a certificate back, but on the iPhone I can only validate that it&#8217;s failing because it doesn&#8217;t tell me anything other than it failed to install.  Through using a packet sniffer, I can validate the following HTTP conversation between the CA/SCEP server and the iPhone.</p>
<p>The iPhone is sending an HTTP GET command with the URI:<br />
Location:       /certsrv/mscep/<br />
Operation:      GetCACert<br />
Message:        hostname</p>
<p>The response from the CA/SCEP machine is StatusCode of 200 with a payload of type &#8216;application/x-x509-ca-ra-cert&#8217;, which I have validated through using another host where I can examine the file that it is a p7b file which is a PKCS #7 file.</p>
<p>The iPhone next issues another GET command, with the URI:<br />
Location:       /certsrv/mscep/<br />
Operation:      GetCACaps<br />
Message:        hostname</p>
<p>The response from the CA/SCEP machine is StatusCode of 200 with a 0 length content.</p>
<p>The iPhone next issues another GET command, with the URI:<br />
Location:       /certsrv/mscep/<br />
Operation:      PKIOperation<br />
Message:        message: MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAaCAJIAEggNnMIAG%0ACSqGSIb3DQEHA6CAMIACAQAxggF9MIIBeQIBADBhMFMxEzARBgoJkiaJk%2FIsZAEZFgNsYWIxFzAV%0ABgoJkiaJk%2FIsZAEZFgdtYXR0bGFiMSMwIQYDVQQDExptYXR0bGFiLU1BVFRMQUJWTTY0MjAwOC1D%0AQQIKYQrpd</p>
<p>To which the CA/SCEP machine responds with StatusCode 200 with a payload of type &#8216;application/x-pki-message.&#8217;  The contents of the payload are included as an attachment.  So, ultimately, it appears that the iPhone doesn&#8217;t like the contents of the application/x-pki-message.</p>
<p>Any thoughts on what could be wrong?</p>
<p>Your help much appreciated.</p>
<p>Jay</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.896 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-07-31 23:40:07 -->
