> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/sono/faqs/certificate-connector.md).

# 証明書コネクタ

Microsoft Certificate Connector for Intune / Active Directory Certificate Services (ADCS) と SCEPman を、導入と運用の負荷の観点で比較します。

| カテゴリ                                      | SCEPman                                                                                                                                                                                                    | PKCS を使用した Microsoft CA                                                                                                                                                                                                                                                                                         | SCEP を使用した NDES                                                                                                                                                                                        |
| ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **セットアップの工数**                             | <p><mark style="color:緑;"><strong>< 30分</strong></mark></p><ul><li><a href="/ja/scepman-nodepuroi/deployment-guides.md">3 段階の展開手順</a> コア機能について</li></ul>                                                   | <p><mark style="color:オレンジ;"><strong>> 2～3 日</strong></mark></p><ul><li>CDP\* の設計と実装</li><li>証明書テンプレートの構成</li><li>構成の互換性 – GPO、サービス アカウント、コネクタのバージョン、...</li></ul>                                                                                                                                              | <p><mark style="color:赤;"><strong>> + 2 日</strong></mark></p><p><em>PKCS に加えて:</em></p><ul><li>NDES 用の追加サーバー</li><li>証明書の種類ごとに 1 台の NDES サーバー</li><li>追加の証明書テンプレートを 2 つ</li><li>デバッグが難しい</li></ul>     |
| **PKI の保守**                               | <ul><li><a href="/ja/azure-gou-cheng/health-check.md">Azure での自動ヘルス監視</a></li></ul>                                                                                                                        | <ul><li><a href="https://github.com/glueckkanja-pki/PKI-Monitoring-Tools">CDP の監視</a></li><li>Certificate Connector の監視</li></ul>                                                                                                                                                                               | <p><em>PKCS に加えて:</em></p><ul><li>Enrollment Agent 証明書の手動更新</li></ul>                                                                                                                                  |
| **サーバーの保守**                               | <ul><li><a href="/ja/azure-gou-cheng/update-strategy.md">自動更新 / パッチ適用</a></li></ul>                                                                                                                        | <ul><li>OS の更新</li><li>監視</li></ul>                                                                                                                                                                                                                                                                             | <p><em>PKCS に加えて:</em></p><ul><li>少なくとも 1 台の追加サーバーに対する OS の更新と監視</li></ul>                                                                                                                             |
| <p><strong>証明書管理</strong><br>発行、更新、失効</p> | <ul><li>完全自動の登録と更新</li><li><a href="/ja/scepman-gou-cheng/device-directories.md">完全自動の失効</a></li><li>手動失効オプション</li></ul>                                                                                   | <ul><li>完全自動の登録と更新</li><li>手動失効（データベースの検索が難しい）</li></ul>                                                                                                                                                                                                                                                        | *PKCS と同様。*                                                                                                                                                                                            |
| **可用性**                                   | <p>単一構成</p><ul><li>App Service の SLA: 稼働率 > 99.95 %</li></ul><p>冗長構成</p><ul><li>Traffic Manager の SLA: 稼働率 > 99.99 %</li></ul>                                                                             | <p>複数の障害モード:</p><ul><li>仮想化プラットフォーム</li><li>オペレーティング システム</li><li>CDP ウェブサーバー</li></ul><p>冗長構成</p><ul><li>待機 CA サーバー</li><li>追加の CDP ウェブサーバー</li><li>バックアップ Certificate Connector 用の待機サーバー</li></ul>                                                                                                            | <p><em>PKCS と同様。</em></p><p>冗長構成</p><ul><li>追加の NDES サーバー</li></ul>                                                                                                                                    |
| **スケーラビリティ**                              | <ul><li><a href="/ja/azure-gou-cheng/azure-sizing/autoscaling.md">数クリックでのオートスケーリングまたは手動スケーリング</a></li><li><a href="/ja/azure-gou-cheng/azure-sizing.md">1 つの SCEPman CA で任意の数のクライアントに対応できます。</a></li></ul> | <ul><li>オートスケーリングなし</li><li>スケーリングには CA クラスターが必要</li><li><a href="https://social.technet.microsoft.com/wiki/contents/articles/9256.active-directory-certificate-services-ad-cs-clustering.aspx">複雑な手動スケーリング</a></li></ul>                                                                                       | <p><em>PKCS と同様。</em></p><ul><li>NDES サーバーを複製するための追加作業</li></ul>                                                                                                                                       |
| **バックアップ**                                | <ul><li>SCEPman はコア機能に対してステートレスです。つまり、バックアップは不要です。</li><li>SCEPman Root CA は Azure Key Vault（リージョン冗長）によって暗黙的にバックアップされます。</li><li>オプションの Storage Account は自動的にバックアップできます。</li></ul>                         | <ul><li>CA データベースの定期バックアップ</li><li>CA キーと構成のバックアップ（高いコンプライアンスおよびセキュリティ要件）</li></ul>                                                                                                                                                                                                                             | *PKCS と同様。*                                                                                                                                                                                            |
| **セキュリティ**                                | <ul><li>ゼロトラスト アプローチ（クラウドネイティブ）に基づいて設計</li><li>最先端の認証方式の使用</li><li>OCSP によるリアルタイムの自動証明書失効（人的エラーは発生しません）</li></ul>                                                                                          | <ul><li>オンプレミス利用向けに設計</li><li>「に対して脆弱<a href="/ja/sono/troubleshooting/certifried.md">certifried attack</a>"</li><li>CA（tier 0 資産）とインターネットの間に追加の通信チャネルがあるため、攻撃対象領域が拡大</li><li>オンプレミス アカウントとクラウド アカウントの使用により、攻撃対象領域が拡大</li><li>CRL の最新性は更新間隔に依存</li><li>OCSP は CRL に基づいており <strong>リアルタイムではない</strong></li></ul> | <p><em>PKCS と同様。</em></p><ul><li>NDES への受信アクセスが必要（<a href="https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/ndes-security-best-practices/ba-p/2832619">tier 0 資産</a>)</li></ul> |
| **柔軟性**                                   | <ul><li>標準化されたインターフェース（SCEP、OCSP、REST）の使用</li><li>複数の MDM ソリューションをサポート</li></ul>                                                                                                                           | <ul><li>Intune のみサポート</li><li>独自の RPC インターフェースにより、レガシーなドメイン参加クライアントで証明書の自動登録が可能</li></ul>                                                                                                                                                                                                                       | <ul><li>複数の MDM ソリューションのサポートが可能（追加の NDES インスタンスが必要）</li></ul>                                                                                                                                          |

\*: CRL 配布ポイント


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/sono/faqs/certificate-connector.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
