SimpleSCEP documentation

Cloud PKI, documented simply.

Self-hosted private PKI with SCEP, ACME, and EST enrollment.

SimpleSCEP is an open-source, self-hosted private PKI. Create certificate authorities, set issuance policy, and enable enrollment protocols in infrastructure you control.

  • SCEP — MDM-managed devices, including Intune, Jamf Pro, Workspace ONE, Ivanti, Kandji, and Mosyle.
  • ACME — automated clients such as cert-manager, Caddy, Traefik, certbot, lego, and acme.sh.
  • EST — network infrastructure such as strongSwan, Cisco IOS, appliances, and IoT fleets.

Production CA private keys are generated in Google Cloud KMS or Azure Key Vault and are non-exportable. Each CA independently selects software- or HSM-backed protection.

How it fits together

Organization
└── Root CA                            (signs nothing but issuing CAs)
    ├── Issuing CA "Devices"
    │   ├── SCEP endpoint  → Intune-managed Windows laptops
    │   └── SCEP endpoint  → Jamf-managed Macs
    └── Issuing CA "Infrastructure"
        ├── ACME endpoint  → Kubernetes ingress, internal TLS
        └── EST endpoint   → branch VPN gateways
  • An organization holds one root CA and one or more issuing CAs beneath it.
  • Each issuing CA carries an issuance profile — the extended key usages it will sign.
  • Each endpoint binds to one issuing CA and carries its own policy: validity, renewal window, permitted subjects, names, and usages.

Endpoints validate requests against their policy and send accepted requests to the issuing CA. Subjects and SANs are copied from the CSR.

Choose a protocol

Protocol Use for Client authenticates with Renewal
SCEP Devices under an MDM Challenge password Signed RenewalReq inside the renewal window
ACME Servers, ingress, service meshes External Account Binding credential, once at registration A new order, on the client's own timer
EST Routers, gateways, appliances, IoT HTTP Basic username and password /simplereenroll

Protocols can use separate issuing CAs and policies.

Next steps