SOTI MobiControl
SCEPman can be integrated with SOTI MobiControl as a Certificate Authority. By connecting both systems through SCEPman's Static SCEP interface, MobiControl-enrolled devices can obtain device certificates from SCEPman.
For more general information about other MDM solutions and SCEPman integration please check here.
Enable SOTI MobiControl Integration
SOTI MobiControl integration of SCEPman can be easily enabled via the following environment variables on SCEPman app service:
Certificate signing requests sent to SCEPman for signing are authenticated with this secure static password Recommendation: Store this secret in Azure KeyVault.
generate a 32 character password
How many days shall certificates issued via SOTI MobiControl be valid
365
Store requested certificates in the Storage Account, in order to show them in SCEPman Certificate Master
true to enable, false to disable
SOTI MobiControl Configuration
Deploy SCEPman RootCA
First, you need to deploy SCEPman RootCA to all endpoints as a trusted root ca, you can download the certificate from SCEPman homepage:

Add Certificate Authority
In Soti MobiControl, navigate to System Settings > Global Settings > Services > Certificate Authority.

Click the Add button to create a new Certificate Authority.

Enter a name for this Certificate Authority.
Select
Generic SCEP
for Certificate Type.Select
SCEP
for Configuration Type.For the Service URL, Copy and Paste the Static MDM URL from your SCEPman Portal.
Enable Use Static Challenge.
Enter the Static Challenge that was created during Step 2. above.
Enable Use SCEP Client.
For the Thumbprint Copy and Paste the CA Thumbprint from your SCEPman Portal.
Set the Retries and Retry Delay as desired (or leave at Default).
Add Certificate Template
Click the Add button to add a Certificate Template.

Enter a name for this MobiControl Template.
Enter a Subject Name.
Leave Alternative Subject empty.
Certificate Target defaults to
Device
.Select the desired option for the remaining fields: Certificate Usage, Key Size, Remove old certificates upon successful renewal, and Key Protection.
Click Add, then Save to save the Template
Click Save to save the Certificate Authority.
Create a Profile in Soti MobiControl to assign this to your devices. There are multiple ways of achieving this in Soti MobiControl, as such, this document will not detail those methodologies.
Last updated
Was this helpful?