SimpleSCEP documentation
Cloud PKI, documented simply.
Self-hosted private PKI with SCEP, ACME, and EST enrollment.
SimpleSCEP is an open-source, self-hosted private PKI. Create certificate authorities, set issuance policy, and enable enrollment protocols in infrastructure you control.
- SCEP — MDM-managed devices, including Intune, Jamf Pro, Workspace ONE, Ivanti, Kandji, and Mosyle.
- ACME — automated clients such as cert-manager, Caddy, Traefik, certbot, lego, and acme.sh.
- EST — network infrastructure such as strongSwan, Cisco IOS, appliances, and IoT fleets.
Production CA private keys are generated in Google Cloud KMS or Azure Key Vault and are non-exportable. Each CA independently selects software- or HSM-backed protection.
How it fits together
Organization
└── Root CA (signs nothing but issuing CAs)
├── Issuing CA "Devices"
│ ├── SCEP endpoint → Intune-managed Windows laptops
│ └── SCEP endpoint → Jamf-managed Macs
└── Issuing CA "Infrastructure"
├── ACME endpoint → Kubernetes ingress, internal TLS
└── EST endpoint → branch VPN gateways
- An organization holds one root CA and one or more issuing CAs beneath it.
- Each issuing CA carries an issuance profile — the extended key usages it will sign.
- Each endpoint binds to one issuing CA and carries its own policy: validity, renewal window, permitted subjects, names, and usages.
Endpoints validate requests against their policy and send accepted requests to the issuing CA. Subjects and SANs are copied from the CSR.
Choose a protocol
| Protocol | Use for | Client authenticates with | Renewal |
|---|---|---|---|
| SCEP | Devices under an MDM | Challenge password | Signed RenewalReq inside the renewal window |
| ACME | Servers, ingress, service meshes | External Account Binding credential, once at registration | A new order, on the client's own timer |
| EST | Routers, gateways, appliances, IoT | HTTP Basic username and password | /simplereenroll |
Protocols can use separate issuing CAs and policies.
Next steps
- Quickstart — from an empty organization to a certificate on a device.
- Core concepts — authorities, endpoints, issuance policy, and identities.
- Certificate authorities — creating, rotating, and retiring authorities.
- Revocation, CRL and OCSP — withdrawing a certificate and telling relying parties.
- Troubleshooting — what the common failures mean.