Can anyone export our CA private key?

No. Production CA keys are generated inside Google Cloud KMS or Azure Key Vault and cannot be exported from the configured provider. Each CA can use software- or HSM-backed protection.

Imported keys cannot be exported from SimpleSCEP, but you may still hold the original. They are marked imported.

Why does our ACME client skip the challenge?

SimpleSCEP creates valid authorizations because public ACME challenges cannot reach private names. Clients authenticate at registration with an External Account Binding credential. See ACME.

Why does EST use a password instead of a client certificate?

SimpleSCEP terminates TLS before the application, so it uses HTTP Basic over server-authenticated TLS as permitted by RFC 7030 §3.2.3. See EST.

Does renewal create another identity?

No. Renewal replaces the certificate for the existing identity.

What happens if we delete an endpoint?

The URL stops responding immediately. Issued certificates remain valid until expiry, but cannot renew. Credentials and enrollment history are deleted.

To stop new enrollments without deleting data, turn the endpoint off.

Can we use our existing certificate authority?

Yes. The private key is wrapped on your machine and never crosses the wire in the clear. See Importing your own CA.

Can we run SCEP and ACME at the same time?

Yes, and EST too. They are independent and can point at different issuing CAs with different policies.

Is there an API we can automate against?

Partly. Challenge and credential routes support JSON but require an administrator session. Service accounts are not yet supported. See the API reference.

Does SimpleSCEP support ACME Renewal Information (ARI)?

No. The directory omits renewalInfo, so clients use their own renewal timers.

How long is a CRL valid, and how fresh is OCSP?

Both are valid for 24 hours and refreshed automatically before they lapse. Revoking a certificate republishes immediately. Revocations requested through Microsoft Intune are collected hourly, so those take up to an hour.

Can an administrator reset another user's second factor?

No. Use a recovery code after losing an authenticator. See Two-factor authentication.

How do we get support?

Search or open a GitHub Issue. Include the version, endpoint type, approximate time, and redacted client error. Do not include passwords, credentials, private keys, or sensitive certificate material. Report suspected vulnerabilities privately through the project's security policy.