> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/de/zertifikatsverwaltung/static-certificates/kandji-1.md).

# Iru (ehemals Kandji)

Stellen Sie Zertifikate in Iru aus, indem Sie SCEPman als externe CA verbinden. Geräte können Zertifikate über SCEPmans statische Schnittstelle und ein hinterlegtes Challenge-Passwort erhalten.

SCEPman kann mit [Iru](https://www.iru.com/) als externe CA über SCEPmans statische Schnittstelle und ein Challenge-Passwort verbunden werden, wodurch registrierte Geräte Zertifikate erhalten können.

Weitere allgemeine Informationen zu anderen MDM-Lösungen und zur SCEPman-Integration finden Sie bitte [hier](/de/zertifikatsverwaltung/static-certificates.md).

## Iru-Integration aktivieren

Die Integration von SCEPman lässt sich auf dem SCEPman App Service ganz einfach über die folgenden Umgebungsvariablen aktivieren:

{% hint style="info" %}
Sie können den SCEPman App Service und den Certificate Master unterscheiden, indem Sie nach dem App Service **ohne** das "-cm" in seinem Namen
{% endhint %}

|                                                                                                Einstellung                                                                                               | Beschreibung                                                                                                                                                                                                                                                                                                                     |                           Wert                          |
| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------------------------------------: |
|                        [AppConfig:StaticValidation:Enabled](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enabled)                       | Validierung durch Drittanbieter aktivieren                                                                                                                                                                                                                                                                                       | ***true*** zum Aktivieren, ***false*** zum Deaktivieren |
|                [AppConfig:StaticValidation:RequestPassword](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword)               | <p>An SCEPman zum Signieren gesendete Zertifikatsanforderungen werden mit diesem sicheren statischen Passwort authentifiziert<br><br><strong>Empfehlung</strong>: Speichern Sie dieses Geheimnis in <a href="/de/scepman-konfiguration/application-settings.md#secure-configuration-in-azure-key-vault">Azure Key Vault</a>.</p> |        *generieren Sie ein 32-stelliges Passwort*       |
|       [AppConfig:StaticValidation:ValidityPeriodDays](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-validityperioddays) (optional)       | Anzahl der Tage, für die über Iru ausgestellte Zertifikate gültig sind                                                                                                                                                                                                                                                           |                           365                           |
| [AppConfig:StaticValidation:EnableCertificateStorage](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enablecertificatestorage) (optional) | Speichern Sie angeforderte Zertifikate im Storage Account, um sie im SCEPman Certificate Master anzuzeigen                                                                                                                                                                                                                       | ***true*** zum Aktivieren, ***false** zum Deaktivieren* |

{% hint style="warning" %}
Nachdem Sie SCEPman-Konfigurationsparameter hinzugefügt oder bearbeitet haben, müssen Sie den App Service neu starten.
{% endhint %}

## Iru-Konfiguration

### SCEPman-Root-Zertifikat

Als ersten Schritt müssen Sie das Root-Zertifikat von SCEPman bereitstellen. Laden Sie dieses CA-Zertifikat über die SCEPman-Website herunter:

![SCEPman-Website](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9170eb0435726398eb43f6fac8abd0d5f35e8cc4%2FSCEPmanHomePage%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(2\).png?alt=media)

Navigieren Sie in Iru zu **Bibliothek** in der linken Navigationsleiste und fügen Sie ein **Zertifikatsbibliothekseintrag** zu Ihrem Blueprint hinzu.

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FfToUgpoUeZOiYNe2xkzi%2F2023-03-09%2012_51_21-Window.png?alt=media&amp;token=df6f66fb-369b-4adf-ab9d-70757354f2f7" alt=""><figcaption><p>Konfigurieren Sie eine Zertifikats-Payload</p></figcaption></figure>

Um das Zertifikat hochzuladen, wählen Sie zuerst **PKCS#1-formatiertes Zertifikat** unter **Zertifikatstyp**, geben Sie anschließend optional einen Namen an, laden Sie Ihr SCEPman-CA-Zertifikat hoch und speichern Sie es schließlich.

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FL8NyfsJR7x2v0j6ybS6g%2F2023-03-09%2014_21_12-KandjiSCEPmanRootCA.png?alt=media&amp;token=a70ff955-bbe2-4b49-9cf4-245964838675" alt=""><figcaption><p>Hinzufügen des SCEPman-Root-CA-Zertifikats</p></figcaption></figure>

### SCEP-Profil

Der zweite Schritt besteht darin, ein **SCEP-Profil** zu Ihrem **Blueprint**. Fügen Sie daher ein neues **SCEP-Bibliothekselement** hinzu und konfigurieren Sie es wie folgt:

* **URL**: Der statische SCEP-Endpunkt von SCEPman, den Sie konfiguriert haben [oben](#enable-kandji-integration)
* **Name:** Ein optionales SAN-Attribut
* **Challenge**: Wird benötigt, um CSR-Anfragen zu authentifizieren, die an SCEPmans statische SCEP-Schnittstelle gesendet werden. Es muss mit dem [Wert](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword) übereinstimmen, den Sie konfiguriert haben [oben](#enable-kandji-integration).
* **Fingerabdruck:** Optionaler CA-Fingerabdruck. Es wird dringend empfohlen, diesen Wert zu konfigurieren, da er ein zusätzliches Maß an Sicherheit bietet. Sie finden ihn auf Ihrer SCEPman-Website als **CA Thumbprint**.
* **Betreff:** Optionaler Subject-Name. **CN=$PROFILE\_UUID** wird automatisch von Iru als Standard-Common-Name hinzugefügt. Iru ermöglicht Ihnen, mehrere CNs hinzuzufügen.

{% hint style="warning" %}
Gelegentlich hatten macOS und iOS Probleme beim automatischen Auswählen von Client-Zertifikaten für Zwecke der Netzwerkauthentifizierung, wenn mehr als zwei CNs hinzugefügt werden.
{% endhint %}

* **Schlüssellänge:** 2048
* **Schlüsselverwendung:** Beides: Signierung und Verschlüsselung

Für weitere Informationen beachten Sie bitte [die Dokumentation von Iru](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile).

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FS84P4c40cLu5H5NCeley%2F2023-03-09%2014_43_19-Kandji.png?alt=media&amp;token=45fdf5b6-6a31-4879-ba87-a7070e76e0c5" alt=""><figcaption><p>Hinzufügen eines SCEP-Profils</p></figcaption></figure>

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FhnTLPcfOXlMpBNOh5Nph%2F2023-03-09%2014_50_23-Kandji.png?alt=media&amp;token=1ed96cb6-861a-4cb7-8511-22e1b0b48763" alt=""><figcaption><p>SCEP-Profilkonfiguration</p></figcaption></figure>

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FbZiDYnqsvxgh8a36zPl3%2F2023-03-09%2014_51_22-Kandji.png?alt=media&amp;token=d2e681dd-f50d-4043-a85a-46bd7396d810" alt=""><figcaption><p>SCEP-Profilkonfiguration</p></figcaption></figure>

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FuiSTD2BxR4utzJ0YACZS%2F2023-03-09%2014_52_52-Kandji.png?alt=media&amp;token=84aa9c64-7b38-4829-b337-cdde8549ab98" alt=""><figcaption><p>SCEP-Profilkonfiguration</p></figcaption></figure>

### Bereitstellungsstatus

Nach dem Speichern des Zertifikats oder SCEP-Profils wechseln Sie zu **Status** um den Bereitstellungsstatus auf **Blueprints** zugewiesenen Geräten.

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FjchSJJzjqEDQxfX8K40s%2F2023-03-09%2015_12_40-Kandji.png?alt=media&amp;token=5b316771-d526-45cc-8ee5-dba4d751e39f" alt=""><figcaption><p>Bereitstellungsstatus</p></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/de/zertifikatsverwaltung/static-certificates/kandji-1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
