> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/overview.md).

# 概要

## SCEPとは何ですか？

通常、（モバイル）デバイスに証明書を配布する必要がある場合、 [Simple Certificate Enrollment Protocol](https://www.rfc-editor.org/rfc/rfc8894.html) (SCEP) が第一候補です。では、SCEPとは何でしょうか？ SCEPは [インターネットドラフト](https://en.wikipedia.org/wiki/Internet_Draft) 標準プロトコルです。インターネットドラフトには技術仕様と技術情報が含まれます。インターネットドラフトはしばしば [Request for Comments](https://en.wikipedia.org/wiki/Request_for_Comments).

SCEPは元々Ciscoによって開発されました。SCEPの主な使命は、ユーザー操作なしでネットワークデバイスに証明書を配布することです。SCEPを利用すると、ネットワークデバイスは自分で証明書を要求できます。

## SCEPmanとは何ですか？

SCEPを「従来の方法」で使う場合、いくつかのオンプレミスコンポーネントが必要です。Microsoft Intuneと [その他のモバイルデバイス管理（MDM）](/ja/use-cases.md#mdm-solutions) ソリューションでは [サードパーティの認証局（CA](https://learn.microsoft.com/en-us/mem/intune/protect/certificate-authority-add-scep-overview)）がSCEPを使用して証明書を発行および検証できるようにします。

オンプレミスコンポーネントをなくすために、私たちはSCEPmanを開発しました。

{% hint style="warning" %}
SCEPmanは、 **認証および通信の暗号化**向けの証明書を発行します。とはいえ、ネットワーク認証、WiFi、VPN、RADIUSなどのサービスに使用するユーザー証明書およびデバイス証明書を配布できます。

**また、** SCEPmanをトランザクション **デジタル署名に** 、つまりMicrosoft OutlookでのS/MIME署名に使用できます。証明書をメッセージ署名に使用する予定がある場合は、Intuneプロファイルの構成で対応する拡張鍵用途を追加する必要があります。SCEPmanの証明書は組織内でのみ信頼されることにご注意ください。SCEPmanは公開信頼された証明書を発行しません。

**使用しないでください** SCEPmanを使用 **メール暗号化に** 、つまりMicrosoft OutlookでのS/MIMEメール暗号化に（鍵管理のための別技術なしで）。 **SCEPプロトコルの性質上、秘密鍵素材をバックアップまたはアーカイブする仕組みは含まれていません。** メール暗号化にSCEPを使用すると、後でメッセージを復号するための鍵を失う可能性があります。
{% endhint %}

### SCEPmanのワークフロー

MDMソリューションとしてIntuneを使用する場合のSCEPmanワークフローの概要です（他のMDMソリューションでも流れは同様です）。最初の図は証明書の発行を示し、2つ目の図は証明書の検証を示します。

証明書発行の流れ：

![](/files/feeedb51a909974a2cc9aae7f6b40163d809862a)

証明書ベース認証中の証明書検証の流れ：

![](/files/7e9a10963c22f9f444a4dee1d0e9b4a79397cc46)

### SCEPmanの機能

SCEPmanは、以下の機能を備えたAzure Web Appです：

* Intuneと互換性のあるSCEPインターフェース [SCEP API](https://learn.microsoft.com/en-us/mem/intune/protect/certificate-authority-add-scep-overview) を特に指します。
* SCEPmanは、次に保存されたCAルートキーで署名された証明書を提供します： **Azure Key Vault**.
* SCEPmanには **OCSPレスポンダー** （下記参照）が含まれており、 [証明書の有効性 / 自動失効](/ja/zheng-ming-shu-guan-li/manage-certificates.md#automatic-revocation) をリアルタイムで提供します
* 多くのシナリオで、Legacy PKIを完全に置き換えます。

SCEPmanは初回インストール時にCAルート証明書を作成します。ただし、何らかの理由で別のCA鍵素材を使用したい場合は、このCA鍵と証明書をAzure Key Vault内の独自のものに置き換えることができます。たとえば、既存の社内ルートCAによって署名されたSub CA証明書を使用したい場合です。

#### Certificate Master

Certificate Masterでは [Enterprise Edition](/ja/editions.md#edition-comparison) のお客様が、SCEP / MDMによる自動登録が不可能なシナリオで（手動で）証明書を発行できるようにします。一般的な例としては、 [TLSサーバー証明書](/ja/zheng-ming-shu-guan-li/certificate-master/tls-server-certificate-pkcs-12.md) または以下向けのユーザー証明書： [スマートカード / YubiKeys](/ja/zheng-ming-shu-guan-li/certificate-master/user-certificate.md)。さらに、Certificate Masterを使うと、管理者は [管理できます](/ja/zheng-ming-shu-guan-li/manage-certificates.md) Intune、Jamf、その他のMDM、EST、 [Enrollment REST API](/ja/zheng-ming-shu-guan-li/api-certificates.md) を通じてSCEPで自動登録されたものでも、Certificate MasterのUI自体から手動で発行されたものでも、SCEPmanによって発行されたあらゆる証明書を。

{% content-ref url="/pages/13fdf762be2175fdd2546ac4ec8454a1421e7523" %}
[Certificate Master](/ja/zheng-ming-shu-guan-li/certificate-master.md)
{% endcontent-ref %}

### SCEPman OCSP（Online Certificate Status Protocol）

この [Online Certificate Status Protocol (OCSP)](https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol) は、証明書の状態を判断するために使用されるインターネットプロトコルです。

通常、OCSPクライアントはOCSPレスポンダーに状態要求を送信します。OCSPレスポンダーは、失効状態やその他の仕組みに基づいて証明書の有効性を検証します。SCEPmanがサポートする証明書失効リスト（CRL）と比べると、OCSP応答は常に最新で、応答は数秒以内に利用可能です。CRLの欠点は、手動で更新する必要があるデータベースに基づいており、大量のデータを持つ可能性があることです。これらの失効メカニズムの詳細な比較を[ 当社ブログの記事で。](https://www.glueckkanja.com/blog/products/2023/05/certificate-revocation-en/)

## はじめに

次のページの手順に従ってSCEPmanを展開し、ユーザー、デバイス、ネットワーク認証のシナリオ向けの証明書発行を自動化してください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
