> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/fr/gestion-des-certificats/static-certificates/kandji-1.md).

# Iru (anciennement Kandji)

Émettez des certificats dans Iru en connectant SCEPman comme AC externe. Les appareils pourront obtenir des certificats à l'aide de l'interface statique de SCEPman et d'un mot de passe de défi inscrit.

SCEPman peut être connecté à [Iru](https://www.iru.com/) en tant que CA externe à l’aide de l’interface statique de SCEPman et d’un mot de passe de challenge, ce qui permet aux appareils inscrits d’obtenir des certificats.

Pour obtenir des informations plus générales sur d’autres solutions MDM et l’intégration de SCEPman, veuillez consulter [ici](/fr/gestion-des-certificats/static-certificates.md).

## Activer l’intégration d’Iru

L’intégration de SCEPman peut être facilement activée via les variables d’environnement suivantes sur l’App Service de SCEPman :

{% hint style="info" %}
Vous pouvez faire la différence entre le SCEPman App Service et le Certificate Master en recherchant l’App Service **sans** dans son nom « -cm »
{% endhint %}

|                                                                                                  Paramètre                                                                                                 | Description                                                                                                                                                                                                                                                                                                                       |                        Valeur                        |
| :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------: |
|                         [AppConfig:StaticValidation:Enabled](/fr/configuration-scepman/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enabled)                        | Activer la validation par des tiers                                                                                                                                                                                                                                                                                               | ***true*** pour activer, ***false*** pour désactiver |
|                 [AppConfig:StaticValidation:RequestPassword](/fr/configuration-scepman/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword)                | <p>Les demandes de signature de certificat envoyées à SCEPman pour signature sont authentifiées avec ce mot de passe statique sécurisé<br><br><strong>Recommandation</strong>: Stockez ce secret dans <a href="/fr/configuration-scepman/application-settings.md#secure-configuration-in-azure-key-vault">Azure KeyVault</a>.</p> |      *générez un mot de passe de 32 caractères*      |
|       [AppConfig:StaticValidation:ValidityPeriodDays](/fr/configuration-scepman/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-validityperioddays) (facultatif)       | Nombre de jours pendant lesquels les certificats émis via Iru sont valides                                                                                                                                                                                                                                                        |                          365                         |
| [AppConfig:StaticValidation:EnableCertificateStorage](/fr/configuration-scepman/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enablecertificatestorage) (facultatif) | Stockez les certificats demandés dans le Storage Account, afin de les afficher dans SCEPman Certificate Master                                                                                                                                                                                                                    | ***true*** pour activer, ***false** pour désactiver* |

{% hint style="warning" %}
Après avoir ajouté ou modifié les paramètres de configuration de SCEPman, vous devez redémarrer l’App Service.
{% endhint %}

## Configuration d’Iru

### Certificat racine SCEPman

Dans un premier temps, vous devez déployer le certificat racine de SCEPman. Téléchargez ce certificat de CA via le site web de SCEPman :

![Site web de SCEPman](https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9170eb0435726398eb43f6fac8abd0d5f35e8cc4%2FSCEPmanHomePage%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(2\).png?alt=media)

Dans Iru, accédez à **Library** dans la barre de navigation de gauche et ajoutez un **Certificate Library Item** à votre Blueprint.

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FfToUgpoUeZOiYNe2xkzi%2F2023-03-09%2012_51_21-Window.png?alt=media&amp;token=df6f66fb-369b-4adf-ab9d-70757354f2f7" alt=""><figcaption><p>Configurer une charge utile de certificat</p></figcaption></figure>

Pour téléverser le certificat, sélectionnez d’abord **certificat au format PKCS #1** sous **Type de certificat**, fournissez ensuite un nom facultatif, téléversez votre certificat CA SCEPman, puis enregistrez-le.

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FL8NyfsJR7x2v0j6ybS6g%2F2023-03-09%2014_21_12-KandjiSCEPmanRootCA.png?alt=media&amp;token=a70ff955-bbe2-4b49-9cf4-245964838675" alt=""><figcaption><p>Ajout du certificat CA racine SCEPman</p></figcaption></figure>

### Profil SCEP

La deuxième étape consiste à ajouter un **Profil SCEP** à votre **Blueprint**. Par conséquent, ajoutez un nouveau **SCEP Library Item** et configurez-le comme ci-dessous :

* **URL**: Le point de terminaison SCEP statique de SCEPman que vous avez configuré [ci-dessus](#enable-kandji-integration)
* **Nom :** Un attribut SAN facultatif
* **Défi**: Est requis pour authentifier les demandes CSR envoyées à l’interface SCEP statique de SCEPman. Il doit correspondre à la [valeur](/fr/configuration-scepman/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword) que vous avez configurée [ci-dessus](#enable-kandji-integration).
* **Empreinte :** Empreinte CA facultative. Il est fortement recommandé de configurer cette valeur, car elle offre un niveau de sécurité supplémentaire. Vous pouvez la trouver sur votre site web SCEPman sous **Empreinte CA**.
* **Sujet :** Nom de sujet facultatif. **CN=$PROFILE\_UUID** sera automatiquement ajouté depuis Iru comme nom commun par défaut. Iru vous permet d’ajouter plusieurs CN.

{% hint style="warning" %}
Parfois, macOS et iOS ont eu des problèmes pour sélectionner automatiquement les certificats clients à des fins d’authentification réseau lorsque plus de deux CN sont ajoutés.
{% endhint %}

* **Taille de clé :** 2048
* **Utilisation de la clé :** Les deux, signature et chiffrement

Pour plus d’informations, veuillez consulter [la documentation d’Iru](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile).

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FS84P4c40cLu5H5NCeley%2F2023-03-09%2014_43_19-Kandji.png?alt=media&amp;token=45fdf5b6-6a31-4879-ba87-a7070e76e0c5" alt=""><figcaption><p>Ajout d’un profil SCEP</p></figcaption></figure>

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FhnTLPcfOXlMpBNOh5Nph%2F2023-03-09%2014_50_23-Kandji.png?alt=media&amp;token=1ed96cb6-861a-4cb7-8511-22e1b0b48763" alt=""><figcaption><p>Configuration du profil SCEP</p></figcaption></figure>

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FbZiDYnqsvxgh8a36zPl3%2F2023-03-09%2014_51_22-Kandji.png?alt=media&amp;token=d2e681dd-f50d-4043-a85a-46bd7396d810" alt=""><figcaption><p>Configuration du profil SCEP</p></figcaption></figure>

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FuiSTD2BxR4utzJ0YACZS%2F2023-03-09%2014_52_52-Kandji.png?alt=media&amp;token=84aa9c64-7b38-4829-b337-cdde8549ab98" alt=""><figcaption><p>Configuration du profil SCEP</p></figcaption></figure>

### État du déploiement

Après avoir enregistré le certificat ou le profil SCEP, basculez vers **Statut** pour vérifier l’état du déploiement sur **Blueprints** les appareils assignés.

<figure><img src="https://129332256-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FjchSJJzjqEDQxfX8K40s%2F2023-03-09%2015_12_40-Kandji.png?alt=media&amp;token=5b316771-d526-45cc-8ee5-dba4d751e39f" alt=""><figcaption><p>État du déploiement</p></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/fr/gestion-des-certificats/static-certificates/kandji-1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
