> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md).

# 静的検証

{% hint style="info" %}
これらの設定は SCEPman App Service にのみ適用し、Certificate Master には適用しないでください。以下を参照してください [SCEPman 設定](/ja/scepman-gou-cheng/application-settings.md).
{% endhint %}

## AppConfig:StaticValidation:Enabled

*Linux: AppConfig\_\_StaticValidation\_\_Enabled*

**値:** *true* または *false* (既定)

**説明:** この設定は、次から証明書を要求するのに役立ちます [他の MDM システム](/ja/zheng-ming-shu-guan-li/static-certificates.md) (つまり、Intune と JAMF 以外)。

* **True**：SCEPman は、パスを持つ追加の SCEP サーバー エンドポイントでリッスンします `/static`. AppConfig:StaticValidation:RequestPassword と組み合わせて使用します。
* **False** (既定値): SCEPman は他の MDM システム (つまり、Intune と JAMF 以外) に証明書を発行しません。

## AppConfig:StaticValidation:DefaultEkus

*Linux: AppConfig\_\_StaticValidation\_\_DefaultEkus*

{% hint style="info" %}
バージョン 2.8 以降に適用
{% endhint %}

**値:** Static エンドポイントを使用した場合に証明書に追加される拡張キー用途 (EKU) の OID です。OID はコンマ、セミコロン、またはスペースで区切ります。既定値は Client Authentication (1.3.6.1.5.5.7.3.2) です

**説明:** 証明書要求に EKU が含まれていない場合、SCEPman はこの設定で定義された EKU を証明書に追加します。もし [AppConfig:UseRequestedKeyUsages](/ja/scepman-gou-cheng/application-settings/certificates.md#appconfig-userequestedkeyusages) が *false*、この設定で定義された EKU は、証明書要求に EKU が含まれている場合でも証明書に追加されます。

## AppConfig:StaticValidation:DefaultKeyUsage

*Linux: AppConfig\_\_StaticValidation\_\_DefaultKeyUsage*

{% hint style="info" %}
バージョン 2.8 以降に適用
{% endhint %}

**値:** EncipherOnly|CrlSign|KeyCertSign|KeyAgreement|DataEncipherment|*KeyEncipherment*|NonRepudiation|*DigitalSignature*|DecipherOnly（デフォルトは *斜体*)

**説明:** 証明書要求に Key Usage が含まれていない場合、SCEPman はこの設定で定義された Key Usage を証明書に追加します。もし [AppConfig:UseRequestedKeyUsages](/ja/scepman-gou-cheng/application-settings/certificates.md#appconfig-userequestedkeyusages) が *false*、この設定で定義された Key Usage は、証明書要求に Key Usage が含まれている場合でも証明書に追加されます。

## AppConfig:StaticValidation:RequestPassword

*Linux: AppConfig\_\_StaticValidation\_\_RequestPassword*

{% hint style="info" %}
バージョン 1.6 以降に適用
{% endhint %}

**値:** *文字列*

**説明:** 証明書を取得するために、Other MDM system がすべての SCEP 要求に含める必要があるチャレンジ パスワードです。次の場合にのみ使用されます [AppConfig:StaticValidation:Enabled](#appconfig-staticvalidation-enabled) が *true*.

この設定は Azure Key Vault で Secret として定義することをお勧めします。Secret の名前は次のとおりである必要があります *AppConfig--StaticValidation--RequestPassword*.

## AppConfig:StaticValidation:ValidityPeriodDays

*Linux: AppConfig\_\_StaticValidation\_\_ValidityPeriodDays*

{% hint style="info" %}
バージョン 1.7 以降に適用
{% endhint %}

**値:** 正の *整数*

**説明:** この設定は、グローバルな [ValidityPeriodDays](/ja/scepman-gou-cheng/application-settings/certificates.md#appconfig-validityperioddays) をさらに短くします。たとえば、ここで 10 日などの低い値を指定して static エンドポイント経由で発行される証明書の有効期間を短縮しつつ、通常のクライアント証明書の有効期間は長いままにできます。

## AppConfig:StaticValidation:EnableCertificateStorage

*Linux: AppConfig\_\_StaticValidation\_\_EnableCertificateStorage*

{% hint style="info" %}
バージョン 2.3 以降に適用

SCEPman Enterprise Edition のみ
{% endhint %}

**値:** *true* または *false* (既定)

**説明:** static エンドポイント経由で証明書を要求すると、この設定が true に設定されている場合、SCEPman は要求された証明書を Azure の Storage Account に保存します *true*。これにより、発行された証明書が SCEPman Certificate Master に表示され、そこで確認および失効できます。これが に設定されている場合 *false*、SCEPman は発行された証明書を保存せず、証明書はログにのみ表示されるか、SCEP クライアントがどこかに保存した場合にのみ表示されます。これが設定されていない場合、動作はグローバル設定に依存します [AppConfig:EnableCertificateStorage](/ja/scepman-gou-cheng/application-settings/basics.md#appconfig-enablecertificatestorage).

## AppConfig:StaticValidation:AllowRenewals <a href="#appconfig-dbcsrvalidation-allowrenewals" id="appconfig-dbcsrvalidation-allowrenewals"></a>

*Linux: AppConfig\_\_StaticValidation\_\_AllowRenewals*

**値:** *true* または *false* (既定)

**説明:** これにより、次の *RenewalReq* 操作をこの SCEP エンドポイントで使用できます。これは、次に追加された証明書タイプに対してのみ機能します *AppConfig:StaticValidation:ReenrollmentAllowedCertificateTypes*.

この操作は、次と [SCEPmanClient ](https://github.com/scepman/scepmanclient)PowerShell モジュールと組み合わせて使用できます。

## AppConfig:StaticValidation:ReenrollmentAllowedCertificateTypes <a href="#appconfig-dbcsrvalidation-reenrollmentallowedcertificatetypes" id="appconfig-dbcsrvalidation-reenrollmentallowedcertificatetypes"></a>

*Linux: AppConfig\_\_StaticValidation\_\_ReenrollmentAllowedCertificateTypes*

**値:** 次の一覧にある証明書タイプのカンマ区切りリスト:

* DomainController
* Static
* IntuneUser
* IntuneDevice
* JamfUser
* JamfUserWithDevice
* JamfUserWithComputer
* JamfDevice
* JamfComputer

**説明:** この設定で指定されたタイプの証明書の更新に SCEP エンドポイントを使用できます。値を指定しない場合、既定では対象タイプはありません。

たとえば、Certificate Master を使用して手動で発行された証明書を更新したい場合は、次を指定します `Static`. さらに Domain Controller 証明書も更新したい場合は、次を指定します `DomainController,Static`.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
