Organization

The tenancy boundary, enforced with database row-level security. Authorities, endpoints, certificates, users, and audit events belong to one organization.

One deployment contains one organization. A user belongs to that organization and holds one role in it.

Root CA

The trust anchor distributed to devices and trust stores. It signs only issuing CAs. Its key is generated securely and cannot be exported.

Roots are long-lived — 10 years by default. Nothing enrolls against a root directly.

Issuing CA

The authority that signs certificates. It has:

  • an issuance profile containing the extended key usages it will sign;
  • its own key, generated and confined securely;
  • a CRL and an OCSP responder at public URLs derived from its ID.

Rotation creates a new key and certificate with the same subject and profile, then retires the old CA.

Endpoint

A device enrollment URL bound to one issuing CA. The protocol and CA cannot change after creation; the name, policy, and authentication methods can.

Validity, renewal window, subject and SAN patterns, permitted usages, and authentication are configured per endpoint.

A disabled endpoint returns 404. Disable it to stop enrollment without deleting its configuration and history.

Avoid shared secrets on endpoints with permissive issuance policies.

Issuance policy

Setting Decides
Validity How long issued certificates last
Renewal window How early a device may renew
Subject pattern Regular expression the CSR's subject must match. Blank allows any
SAN pattern Regular expression each subject alternative name must match. Blank allows any
Permitted extended key usages The ceiling on what a request may ask for

Patterns accept or reject a CSR; they do not modify it. See Issuance profiles and key usages.

Identity

An identity is a distinct certificate subject with a live certificate.

  • A device that renews every month holds twelve certificates in a year and occupies one identity.
  • An MDM that enrolls the same device twice produces two certificates and one identity.
  • Renewals preserve the identity while replacing its certificate.

Key protection

Production CA private keys are generated in the configured Google Cloud KMS or Azure Key Vault provider and cannot be exported. Each CA selects software or HSM protection and shows its export posture:

Posture Meaning
Non-exportable Generated inside the configured KMS provider; the key has never existed outside it
Imported You generated the key and imported it wrapped. SimpleSCEP's copy is non-exportable, but it is not the only copy

Deleting an authority schedules its key version for destruction.