Import an existing authority to keep your current trust hierarchy. The wrapped-key import workflow currently requires Google Cloud KMS; Azure Key Vault import is not supported in this release.

Select Import your own CA on the Certificate Authorities page.

You can import a root or an issuing CA.

Import process

The private key is wrapped before upload:

  1. Upload the certificate. Paste the CA certificate PEM, and its chain if it is an issuing CA. It must be a CA certificate, the chain must actually chain, and any request containing private key material is refused.
  2. SimpleSCEP provisions an import target and returns a wrapping public key.
  3. You wrap the key locally with that public key, on a machine you trust with the plaintext key, and paste the base64 wrapped blob — see Wrap the key locally below.
  4. KMS unwraps it into a non-exportable key version. The wrapping key and import job cannot be reused.

The job moves through preparing → ready to wrap → importing → completed. Failures include a reason. You can cancel an incomplete job; abandoned jobs expire.

A CA import job at the ready to wrap step

Wrap the key locally

The "ready to wrap" step repeats these commands with your job's wrapping public key filled in — this section is the reference copy, for scripting the wrap or understanding what it does. Save that public key as wrapping-key.pem, and start from ca-key.pem, the private key's own PEM file.

The wrapping method is a 4096-bit RSA-OAEP-SHA256 key wrapping a one-time AES-256 key, which in turn wraps the CA private key with AES-256-KWP (RFC 5649). Two steps rather than one because RSA-OAEP has no room to wrap a private key directly — the AES key is small enough to fit, and AES-KWP has no such limit for what it wraps.

# 1. PKCS8 DER, unencrypted — the format the key provider requires the
#    target key in.
openssl pkcs8 -topk8 -nocrypt -in ca-key.pem -outform DER -out target-key.der

# 2. A one-time AES-256 key, generated fresh for this import only.
openssl rand 32 > temp_aes_key.bin

# 3. Wrap the AES key with the wrapping public key (RSA-OAEP, SHA-256).
openssl pkeyutl -encrypt -pubin -inkey wrapping-key.pem \
  -in temp_aes_key.bin -out wrapped_aes_key.bin \
  -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256 -pkeyopt rsa_mgf1_md:sha256

# 4. Wrap the target key with the AES key (AES-256-KWP).
openssl enc -id-aes256-wrap-pad -K $(xxd -p temp_aes_key.bin | tr -d '\n') \
  -iv A65959A6 -in target-key.der -out wrapped_target_key.bin

# 5. Concatenate — wrapped AES key first, then the wrapped target key —
#    and base64 the result. Paste this into "Wrapped key (base64)".
cat wrapped_aes_key.bin wrapped_target_key.bin | base64 -w0

# 6. Remove the plaintext intermediates this produced.
shred -u temp_aes_key.bin target-key.der

Requires OpenSSL 3.x, for -id-aes256-wrap-pad. base64 -w0 is GNU coreutils; on macOS, base64 -b 0 is the equivalent.

This same method covers every supported algorithm — ECDSA P-256, ECDSA P-384, RSA 3072, RSA 4096 — since it wraps the key's DER bytes rather than anything specific to its algorithm. Only ca-key.pem changes.

Before you import

  • You still hold a copy of the key. SimpleSCEP marks the authority as imported even though its copy cannot be exported.
  • The key must match the certificate. A mismatch is caught at import, not at first signature.
  • Supported algorithms are the same as for created authorities: ECDSA P-256, ECDSA P-384, RSA 3072, RSA 4096.
  • A root can only be imported if the organization has no root.

After importing

The imported CA behaves like any other: it binds to endpoints, publishes a CRL, answers OCSP, and can be deactivated or rotated.

Rotating an imported CA creates a new non-exportable key using the protection selected for the replacement CA.

Deleting an imported CA schedules SimpleSCEP's copy of the key version for destruction. It does not, and cannot, do anything about your copy.