> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/use-cases.md).

# ユースケース

このページは、あなたに **概要** を **一般的なユースケース** と、クライアントが SCEPman を活用しているシナリオを紹介することを目的としています。各ベンダー製ソリューションの細かな点すべてについてサポートすることはできませんが、この概要が、あまり一般的でない、あるいは極端なユースケースであなたを圧倒することなく、SCEPman があなたのシナリオにも適合するかどうかを素早く判断する助けになれば幸いです。迷ったら、 [お気軽にご質問ください](https://www.scepman.com/drop-a-question).

## 安全なWiFiとネットワークアクセス

SCEPman が発行する証明書は、WiFi、有線/LAN、VPN 向けの証明書ベースのネットワーク認証（802.1X / EAP-TLS）の目的で広く利用されており、通常は RADIUS または RadSec プロトコルに対応したネットワークアクセス制御（NAC）サービスと併用されます。このようなサービスの代表例は、

* [RADIUSaaS](https://www.radius-as-a-service.com/)
* Aruba ClearPass
* Cisco ISE / Cisco ASA
* Azure VPN Gateway / Azure AlwaysOn VPN
* Fortinet FortiGate
* Palo Alto GlobalProtect

ノートPC、PC、Mac といった一般的なユーザー中心のクライアントデバイスに加えて、 **キオスク端末** POS やセルフレジシステム、スキャナー/バーコードガン、顧客端末などには、安全なネットワーク認証のために SCEPman の証明書が搭載されることがよくあります。

## 証明書ベースの認証

TLSクライアント認証のために、SCEPman でユーザー認証証明書を登録できます。これにより、次のような Web サイトやサービスへの認証が可能になります。

* 社内Webアプリケーション
* [Windows](/ja/zheng-ming-shu-guan-li/api-certificates/api-enrollment/windows-server.md) または [Linux](/ja/zheng-ming-shu-guan-li/api-certificates/api-enrollment/linux-server.md) サーバー
* Microsoft 365
  * Exchange Online
  * Azure Active Directory (AAD) / Azure CBA（以下を含む [CRLサポート](/ja/scepman-gou-cheng/application-settings/crl.md)）、たとえば [NIST 800-63, Rev. 4](https://www.nist.gov/identity-access-management/roadmap-nist-special-publication-800-63-4-digital-identity-guidelines)
* その他のクラウドサービス
* リモート デスクトップ (RDP) 接続
  * AVD
  * Windowsサーバー管理 / PAW

## TLSインスペクション

SCEPman は [サブCA証明書を発行できます](/ja/zheng-ming-shu-guan-li/certificate-master/sub-ca-certificate.md) 。これは、ファイアウォールアプライアンスおよび次のようなサービスでのTLSインスペクション向けです。

* [Azure Firewall](https://learn.microsoft.com/en-us/azure/firewall/premium-certificates)
* Global Secure Access (GSA)（[Microsoft Entra Internet Access](https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-transport-layer-security))
* その他のファイアウォールアプライアンス

## MDMソリューション

関連する構成プロファイルの展開を自動化し、証明書を最新の状態に保つ（自動更新）ために、SCEPman を MDM ソリューションと併用することをお勧めします。SCEPman は Microsoft Endpoint Manager/Intune および Jamf Pro とネイティブに統合されますが、お客様の中には他の MDM ソリューションと併用して SCEPman を導入し、成功している例もあります。

以下の表では、最も一般的に使用されている MDM ソリューションの概要と、証明書失効がどのように／可能かどうかを示しています。

| MDMソリューション                                                                                        | 対応プラットフォーム                                                                                                                    | 発行 & 自動更新                           | 自動失効                         | 手動失効                                                                               | リンク                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------- | ---------------------------- | ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p><a href="/pages/d707fc5c0d1b5e571123c01e0b8435ced93eec79">Intune /<br>Endpoint Manager</a></p> | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br><a href="/pages/ad2aa1c1a27293de7403f190cfd8bd29c3b85d4f">Linux</a></p> | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:   | <p><span data-gb-custom-inline data-tag="emoji" data-code="2611">☑️</span><br></p> | [Microsoft Docs](https://docs.microsoft.com/en-us/mem/intune/protect/certificates-profile-scep)                                                                                                                                                                                                                                                                          |
| [Active Directory / Group Policy (GPO)](/ja/zheng-ming-shu-guan-li/active-directory.md)           | Windows                                                                                                                       | :ballot\_box\_with\_check:          |                              |                                                                                    |                                                                                                                                                                                                                                                                                                                                                                          |
| [Jamf Pro](/ja/zheng-ming-shu-guan-li/jamf.md)                                                    | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                 | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:   | :ballot\_box\_with\_check:                                                         | [Jamf Technical Paper](https://docs.jamf.com/technical-papers/jamf-pro/scep-proxy/10.0.0/Introduction.html)                                                                                                                                                                                                                                                              |
| [GSuite / Google Workspace](/ja/zheng-ming-shu-guan-li/static-certificates.md)                    | <p>ChromeOS<br>Android</p>                                                                                                    | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Google Support Docs](https://support.google.com/chrome/a/answer/11053129?hl=en)                                                                                                                                                                                                                                                                                         |
| [Airwatch / WorkspaceONE UEM](/ja/zheng-ming-shu-guan-li/static-certificates.md)                  | <p>macOS<br>iOS</p>                                                                                                           | :ballot\_box\_with\_check: (自動更新なし) |                              | :ballot\_box\_with\_check:                                                         | [VMware Support Docs](https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2011/Certificate_Authority_Integrations/GUID-EF7C4D44-9480-4AD1-91E3-EA4F02448F5A.html)                                                                                                                                                                                                        |
| [Mosyle](/ja/zheng-ming-shu-guan-li/static-certificates/mosyle.md)                                | <p>macOS</p><p>iOS<br>iPadOS</p>                                                                                              | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         |                                                                                                                                                                                                                                                                                                                                                                          |
| [SOTI MobiControl](/ja/zheng-ming-shu-guan-li/static-certificates.md)                             | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android<br>Ubuntu</p>                                                              | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         | <p><a href="https://www.soti.net/mc/help/v14.1/en/console/reference/dialogs/globalsettings/certificates/certificate_authorities.html?hl=certificate%2Cauthority#globalsetting_certificate_authorities__genericscep">Soti Docs - External CA</a><br><a href="https://www.soti.net/mc/help/v14.1/en/console/system/certificates/add.html">Soti Docs - SCEP Profile</a></p> |
| [Kandji](/ja/zheng-ming-shu-guan-li/static-certificates/kandji-1.md)                              | <p>macOS<br>iOS<br>iPadOS</p>                                                                                                 | :ballot\_box\_with\_check:          | :ballot\_box\_with\_check:\* | :ballot\_box\_with\_check:                                                         | [Kandji Docs](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile)                                                                                                                                                                                                                                                                             |
| [ManageEngine](/ja/zheng-ming-shu-guan-li/static-certificates.md)                                 | <p>Windows<br>macOS<br>iOS</p><p>iPadOS<br>Android</p>                                                                        | :ballot\_box\_with\_check:          |                              | :ballot\_box\_with\_check:                                                         | [ManageEngine Docs](https://www.manageengine.com/mobile-device-management/help/certificate_management/mdm_integrating_generic_scep.html)                                                                                                                                                                                                                                 |

\*: ユーザーオブジェクトが Microsoft Entra ID (Azure AD) から同期されている場合にのみ、ユーザー型証明書で動作します。

## オンプレミスからクラウドへの移行

SCEPman はクラウドネイティブで汎用的な PKI であるため、オンプレミスのインフラをクラウドへ移行する多くのお客様が、オンプレミスの Microsoft PKI（ADCS および NDES）を完全に置き換えるために SCEPman を使用しています。SCEPman を使えば、これは次のようなエンドポイントデバイスで可能です。

* ドメイン参加済み、
* ハイブリッド参加済み、または&#x20;
* Entra ID参加済み。

## IoTデバイス

SCEPman は IoT デバイスに証明書を供給するために利用できます。そのため、SCEPman は ECC CA をサポートしており、計算資源が限られたデバイスやバッテリー駆動に依存するデバイス上で、性能と省電力に最適化された暗号アルゴリズムを利用できます。SCEPman の柔軟性により、有効期間の長い証明書を発行できるため、定期的な証明書更新を必要とせず長期のオフライン運用が可能です。さらに、Microsoft Entra ID (Azure AD) ベースの認証を用いた SCEPman の REST API を活用することで、組立ライン上で便利に証明書を登録できます。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/use-cases.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
