> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/de/zertifikatsverwaltung/jamf/general.md).

# Allgemeine Konfiguration

SCEPman kann über den dedizierten Jamf-Endpunkt von SCEPman als externe CA mit Jamf Pro verbunden werden, sodass registrierte Benutzer und Geräte Zertifikate erhalten können. Jamf Pro fungiert als SCEP-Proxy und vermittelt die Kommunikation zwischen SCEPman und Jamf-Pro-Geräten.

## Jamf-Integration aktivieren

Die Jamf-Integration von SCEPman lässt sich einfach über die folgenden Umgebungsvariablen auf **SCEPman-App-Service**:

| Einstellung                                                                                                                                                                                        | Beschreibung                                                                                                                                                                                                                                                                  | Beispiel                     |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- |
| [AppConfig:JamfValidation:Enabled](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-enabled)                                              | Möchten Sie SCEPman mit Jamf verwenden?                                                                                                                                                                                                                                       | true                         |
| [AppConfig:JamfValidation:RequestPassword](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-requestpassword)                              | <p>Jamf authentifiziert seine Zertifikatsanforderungen bei SCEPman mit diesem sicheren Passwort.</p><p>Erwägen Sie, dies als Geheimnis in Ihrem SCEPman <a href="/de/scepman-konfiguration/application-settings.md#secure-configuration-in-azure-key-vault">KeyVault</a>.</p> | max. *32-stelliges Passwort* |
| [AppConfig:JamfValidation:ValidityPeriodDays](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-validityperioddays) (optional)             | Wie viele Tage dürfen über Jamf ausgestellte Zertifikate höchstens gültig sein?                                                                                                                                                                                               | 365                          |
| [AppConfig:JamfValidation:EnableCertificateStorage](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-enablecertificatestorage) (optional) | Aktivieren Sie diese Einstellung, um Jamf-Zertifikate im Certificate Master zu speichern                                                                                                                                                                                      | wahr oder falsch (Standard)  |

## API-Verbindung

SCEPman muss mit der Jamf-API verbunden werden, um den Status der eingebundenen Clients zu überprüfen. Dies wird für den Widerruf von Zertifikaten verwendet.

[Siehe die Jamf-Dokumentation](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html) darüber, wie eine API-Rolle und ein API-Client erstellt werden. Der API-Client muss eine Rolle mit diesen Berechtigungen haben:

* Mobile Devices lesen
* Computer lesen
* Benutzer lesen

Bitte definieren Sie die folgenden Umgebungsvariablen in Ihrem **SCEPman App Service**:

| Einstellung                                                                                                                                                     | Beschreibung                                                                                                                                                                                                                                       | Beispiel                                                                                                                                     |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| [AppConfig:JamfValidation:URL](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-url)                   | Die URL Ihrer Jamf-Instanz                                                                                                                                                                                                                         | `https://contoso.jamfcloud.com`                                                                                                              |
| [AppConfig:JamfValidation:ClientID](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-clientid)         | Der Bezeichner des Jamf-API-Clients                                                                                                                                                                                                                | Siehe [Jamf-Client-ID](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html#ariaid-title3)     |
| [AppConfig:JamfValidation:ClientSecret](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-clientsecret) | <p>Der Wert des Client Secrets für die Konfiguration des API-Clients.</p><p>Erwägen Sie, dies als Geheimnis in Ihrem SCEPman <a href="/de/scepman-konfiguration/application-settings.md#secure-configuration-in-azure-key-vault">KeyVault</a>.</p> | Siehe [Jamf-Client-Secret](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html#ariaid-title4) |

{% hint style="warning" %}
Die Classic API von Jamf Pro unterstützt seit Version 10.35.0 die Bearer-Authentifizierung. Seit Version 10.36.0 gibt es eine Einstellung, um die vorherige Authentifizierungsmethode, die Basic Authentication, zu deaktivieren. Eine zukünftige Jamf-Version, die für August bis Dezember 2022 geplant ist, wird die Unterstützung für Basic Authentication entfernen. SCEPman 2.0 und niedriger unterstützen für die Classic API nur Basic Authentication, während SCEPman 2.1 und höher Bearer Authentication verwendet. Um Bearer Authentication zu verwenden, müssen Sie auf SCEPman 2.1 oder höher aktualisieren.
{% endhint %}

## Verbindung zur externen CA

Öffnen Sie die Jamf-Pro-Einstellungen und wählen Sie unter "Global Management" "PKI Certificates":

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-ba2b5fe78590c9c592ef0d65cdf14fe238acda0a%2Fimage%20\(23\).png?alt=media)

Wechseln Sie zum Tab "Management Certificate Template", "External CA" und aktivieren Sie den Bearbeitungsmodus. Bitte aktivieren Sie Jamf Pro als "SCEP Proxy für Konfigurationsprofile":

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-c9a89bf1790dfb161703eaf77a5afcb9b33bcd8b%2Fimage%20\(26\).png?alt=media)

Bitte füllen Sie die folgenden Felder aus und speichern Sie die Konfiguration:

| Feld                                   | Beschreibung                                                                                        | Beispiel/Wert                                                                                                                                                              |
| -------------------------------------- | --------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **URL**                                | <p>URL zu SCEPman</p><p>Vergessen Sie <strong>NICHT</strong> den <strong>/jamf</strong> am Ende</p> | <https://scepman.contoso.com/jamf>                                                                                                                                         |
| **Name**                               | Name der Instanz                                                                                    | SCEPman Contoso                                                                                                                                                            |
| **Betreff**                            | Einträge gemäß X.500-Standard                                                                       | O=Contoso                                                                                                                                                                  |
| **Challenge-Typ**                      | Challenge-Typ zur Überprüfung der Zertifikatsausstellung                                            | Static                                                                                                                                                                     |
| **(Prüf-)Challenge**                   | vorab geteilter geheimer Wert (Challenge)                                                           | in SCEPman definiert über [AppConfig](/de/scepman-konfiguration/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-requestpassword) Parameter |
| Schlüsselgröße                         | Schlüsselgröße in Bits                                                                              | 2048                                                                                                                                                                       |
| Als digitale Signatur verwenden        |                                                                                                     | Ja (falls erforderlich)                                                                                                                                                    |
| Für Schlüsselverschlüsselung verwenden |                                                                                                     | Ja (falls erforderlich)                                                                                                                                                    |
| Fingerabdruck                          | Fingerabdruck des SCEPman-CA-Zertifikats (SHA-1)                                                    | im SCEPman-Dashboard sichtbar ("CA Thumbprint")                                                                                                                            |

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-706cea0b6e3d717ff4d599d924edd31a98ff407b%2F2021-10-21%2020_37_05-Edit%20PKI%20Certificates%20PKI%20Certificates_%20and%201%20more%20page%20-%20Work%20-%20Microsoft%E2%80%8B%20Edge.png?alt=media)

### Signierzertifikat

Bei Verwendung einer externen CA verlangt Jamf, dass Sie das CA-Zertifikat hinzufügen, damit Jamf vergleichen kann, ob die Zertifikate korrekt signiert sind. Jamf erlaubt das Hinzufügen eines CA-Zertifikats jedoch nur, wenn Sie auch ein Signierzertifikat mit einem entsprechenden privaten Schlüssel hinzufügen. Jamf verwendet dieses Signierzertifikat, um Zertifikatsanforderungen zu signieren, die an SCEPman gesendet werden. SCEPman prüft die Signatur auf Anforderungen jedoch nicht und akzeptiert sogar unsignierte Anforderungen (z. B. von Intune), da die Gültigkeit der Anforderung ausschließlich aus der Verwendung des richtigen, in Jamf konfigurierten Challenge-Passworts resultiert.

{% tabs %}
{% tab title="OpenSSL" %}

```shellscript
openssl req -x509 -newkey rsa:4096 -keyout tempKey.key -out tempCert.pem -sha256 -days 3650 -nodes -subj "/CN=JAMF Signierzertifikat für SCEPman"
openssl pkcs12 -export -out SigningCert.pfx -inkey ./tempKey.key -in ./tempCert.pem -passout pass:password
# Temporäre Dateien entfernen
rm tempKey.key
rm tempCert.pem
```

{% endtab %}

{% tab title="PowerShell" %}

```powershell
$cert = New-SelfSignedCertificate -Subject "CN=JAMF Signierzertifikat für SCEPman" -CertStoreLocation "Cert:\CurrentUser\My" -NotAfter (Get-Date).AddYears(10)
$pfxBytes = $cert.Export([System.Security.Cryptography.X509Certificates.X509ContentType]::Pfx, "password")
[System.IO.File]::WriteAllBytes("c:\temp\jamf.pfx", $pfxBytes)
```

{% endtab %}
{% endtabs %}

Klicken Sie dann in der External-CA-Konfiguration von Jamf auf "Change Signing and CA Certificates"

![](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-4c7abd11c59ea4578210eff6b229c0b610bd5f08%2Fjamfsigningcertificate.png?alt=media)

Laden Sie im Assistenten die PFX-Datei mit dem Signierzertifikat bei Jamf hoch, wenn danach gefragt wird (Hinweis: Pkcs#12 und PFX sind Synonyme). Geben Sie in den nächsten Schritten das Passwort für die PFX-Datei ein und bestätigen Sie die Auswahl des Signierzertifikats. Im Tab "Upload CA Certificate" müssen Sie das SCEPman-CA-Zertifikat hochladen. Sie können das SCEPman-CA-Zertifikat erhalten, indem Sie oben rechts auf der Startseite Ihrer SCEPman-Instanz auf den Link "Get CA Certificate" klicken. Bestätigen Sie abschließend Ihre Änderungen.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/de/zertifikatsverwaltung/jamf/general.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
