> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/overview.md).

# 概要

## SCEPとは何ですか？

通常、（モバイル）デバイスに証明書を配布する必要がある場合、 [シンプル証明書登録プロトコル](https://www.rfc-editor.org/rfc/rfc8894.html) (SCEP) が第一選択です。では、SCEPとは何でしょうか？ SCEPは [インターネットドラフト](https://en.wikipedia.org/wiki/Internet_Draft) 標準プロトコルです。インターネットドラフトには技術仕様と技術情報が含まれます。インターネットドラフトはしばしば、 [コメント要求](https://en.wikipedia.org/wiki/Request_for_Comments).

SCEPはもともとCiscoによって開発されました。SCEPの中心的な使命は、ユーザーの操作なしにネットワークデバイスへ証明書を配布することです。SCEPを使うことで、ネットワークデバイスは自分で証明書を要求できます。

## SCEPmanとは何ですか？

SCEPを「従来の方法」で使う場合、いくつかのオンプレミス構成要素が必要です。Microsoft Intune と [その他のモバイルデバイス管理（MDM）](/ja/use-cases.md#mdm-solutions) ソリューション [サードパーティの認証局（CA](https://learn.microsoft.com/en-us/mem/intune/protect/certificate-authority-add-scep-overview)）がSCEPを使用して証明書を発行し、検証できるようにします。

オンプレミス構成要素を不要にするために、私たちはSCEPmanを開発しました。

{% hint style="warning" %}
SCEPmanは、次の用途向けの証明書を発行します。 **認証および転送暗号化を目的とした**。とはいえ、ネットワーク認証、WiFi、VPN、RADIUS、その他類似サービスで使用するユーザー証明書およびデバイス証明書を配布できます。

**使用できます。** SCEPmanをトランザクション向けに使用できます。 **デジタル署名** つまり、Microsoft Outlook での S/MIME 署名です。証明書をメッセージ署名に使う予定であれば、Intune プロファイル構成で対応する拡張キー使用法を追加する必要があります。SCEPman の証明書は組織内でのみ信頼されることにご留意ください。SCEPman は、公開で信頼される証明書を発行しません。

**使用しないでください** SCEPmanを **メール暗号化に** つまり、Microsoft Outlook での S/MIME メール暗号化（鍵管理用の別技術なし）です。SCEPプロトコルの性質上、 **秘密鍵材料をバックアップまたはアーカイブする機構は含まれていません。** メール暗号化にSCEPを使用した場合、後でメッセージを復号するための鍵を失う可能性があります。
{% endhint %}

### SCEPmanのワークフロー

Intune を MDM ソリューションとして使用する場合の SCEPman のワークフローの概要です（他の MDM ソリューションでも流れは同様です）。最初の図は証明書の発行を、2つ目の図は証明書の検証を示しています。

証明書発行のプロセス：

![](/files/f0e08ec64b025e7a3ba834a22811174ad3c9db62)

証明書ベース認証中の証明書検証のプロセス：

![](/files/b0d124475749c575728a650855a10167c56cf940)

### SCEPmanの機能

SCEPman は、次の機能を備えた Azure Web App です：

* Intune と互換性のある SCEP インターフェース [SCEP API](https://learn.microsoft.com/en-us/mem/intune/protect/certificate-authority-add-scep-overview) 特に。
* SCEPman は、次に保存された CA ルートキーで署名された証明書を提供します。 **Azure Key Vault**.
* SCEPman には **OCSP レスポンダー** （下記参照）が含まれており、 [証明書の有効性 / 自動失効](/ja/zheng-ming-shu-guan-li/manage-certificates.md#automatic-revocation) をリアルタイムで
* 多くのシナリオで、レガシー PKI を完全に置き換えます。

SCEPman は初回インストール時に CA ルート証明書を作成します。ただし、何らかの理由で別の CA 鍵素材を使用したい場合は、この CA 鍵と証明書を Azure Key Vault 内の独自のものに置き換えることが可能です。たとえば、既存の社内 Root CA によって署名された Sub CA 証明書を使いたい場合です。

#### Certificate Master

Certificate Master では [Enterprise Edition](/ja/editions.md#edition-comparison) SCEP / MDM による自動登録が不可能なシナリオで、顧客が（手動で）証明書を発行できます。一般的な例としては、次のような証明書の発行があります： [TLS サーバー証明書](/ja/zheng-ming-shu-guan-li/certificate-master/tls-server-certificate-pkcs-12.md) または、次の用途のユーザー証明書： [スマートカード / YubiKey](/ja/zheng-ming-shu-guan-li/certificate-master/user-certificate.md)。さらに、Certificate Master を使うと、管理者は [管理できます](/ja/zheng-ming-shu-guan-li/manage-certificates.md) SCEPman によって発行されたあらゆる証明書を、Intune、Jamf、その他の MDM、EST、 [Enrollment REST API](/ja/zheng-ming-shu-guan-li/api-certificates.md) 、または Certificate Master UI 自体から手動で登録されたものかどうかにかかわらず、管理できます。

{% content-ref url="/pages/13fdf762be2175fdd2546ac4ec8454a1421e7523" %}
[Certificate Master](/ja/zheng-ming-shu-guan-li/certificate-master.md)
{% endcontent-ref %}

### SCEPman OCSP（Online Certificate Status Protocol）

この [Online Certificate Status Protocol（OCSP）](https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol) は、証明書の状態を判定するために使用されるインターネットプロトコルです。

通常、OCSP クライアントは OCSP レスポンダーに状態要求を送信します。OCSP レスポンダーは、失効状態やその他の仕組みに基づいて証明書の有効性を検証します。SCEPman がサポートする証明書失効リスト（CRL）と比較すると、OCSP 応答は常に最新であり、応答は数秒以内に利用可能です。CRL には、手動で更新しなければならないデータベースに基づいており、データ量が多くなる可能性があるという欠点があります。これらの失効メカニズムの詳細な比較をお読みください[ は、当社ブログの記事にあります。](https://www.glueckkanja.com/blog/products/2023/05/certificate-revocation-en/)

## はじめに

次のページの手順に従って SCEPman を展開し、ユーザー、デバイス、ネットワーク認証シナリオ向けの証明書発行を自動化してください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
