> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/jamf/general.md).

# 一般設定

SCEPman は、SCEPman 専用の Jamf エンドポイントを介して外部 CA として Jamf Pro に接続でき、登録済みのユーザーとデバイスが証明書を取得できるようにします。Jamf Pro は SCEP Proxy として動作し、SCEPman と Jamf Pro デバイス間の通信を中継します。

## Jamf 連携を有効化

SCEPman の Jamf 連携は、次の環境変数を使って簡単に有効化できます **SCEPman アプリ サービス**:

| 設定                                                                                                                                                                                | 説明                                                                                                                                                                                                                      | 例                  |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |
| [AppConfig:JamfValidation:Enabled](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-enabled)                                        | SCEPman と Jamf を使用しますか？                                                                                                                                                                                                 | true               |
| [AppConfig:JamfValidation:RequestPassword](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-requestpassword)                        | <p>この安全なパスワードで、Jamf は SCEPman への証明書要求を認証します。</p><p>これを SCEPman のシークレットとして KeyVault に追加することを検討してください <a href="/pages/133e9cb84e56c5cc3ac0cff5eac5341191a43f14#secure-configuration-in-azure-key-vault">KeyVault</a>.</p> | 最大 *32 文字のパスワード*   |
| [AppConfig:JamfValidation:ValidityPeriodDays](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-validityperioddays) （任意）             | Jamf 経由で発行された証明書は、最大何日間有効にしますか？                                                                                                                                                                                         | 365                |
| [AppConfig:JamfValidation:EnableCertificateStorage](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-enablecertificatestorage) （任意） | この設定を有効にすると、Jamf 証明書を Certificate Master に保存できます                                                                                                                                                                        | true または false（既定） |

## API 接続

オンボード済みクライアントの状態を確認するために、SCEPman は Jamf API に接続されている必要があります。これは証明書の失効に使用されます。

[Jamf のドキュメントを参照してください](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html) API ロールと API クライアントの作成方法については、Jamf のドキュメントを参照してください。API クライアントには、次の権限を持つロールが必要です:

* モバイルデバイスの読み取り
* コンピューターの読み取り
* ユーザーの読み取り

SCEPman の次の環境変数を定義してください **SCEPman App Service**:

| 設定                                                                                                                                                   | 説明                                                                                                                                                                                                            | 例                                                                                                                                         |
| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| [AppConfig:JamfValidation:URL](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-url)                   | Jamf インスタンスの URL                                                                                                                                                                                              | `https://contoso.jamfcloud.com`                                                                                                           |
| [AppConfig:JamfValidation:ClientID](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-clientid)         | Jamf API クライアントの識別子                                                                                                                                                                                           | 参照 [Jamf クライアント ID](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html#ariaid-title3)     |
| [AppConfig:JamfValidation:ClientSecret](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-clientsecret) | <p>API クライアント構成の Client Secret の値。</p><p>これを SCEPman のシークレットとして KeyVault に追加することを検討してください <a href="/pages/133e9cb84e56c5cc3ac0cff5eac5341191a43f14#secure-configuration-in-azure-key-vault">KeyVault</a>.</p> | 参照 [Jamf クライアント シークレット](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html#ariaid-title4) |

{% hint style="warning" %}
Jamf Pro の Classic API は、10.35.0 以降で Bearer 認証をサポートします。10.36.0 以降には、以前の認証方式である Basic 認証を無効化する設定があります。2022 年 8 月〜12 月に予定されている将来の Jamf バージョンでは、Basic 認証のサポートが削除されます。SCEPman 2.0 以前は Classic API で Basic 認証のみをサポートし、SCEPman 2.1 以降は Bearer 認証を使用します。Bearer 認証を使用するには、SCEPman 2.1 以降にアップグレードする必要があります。
{% endhint %}

## 外部 CA への接続

Jamf Pro の設定を開き、「グローバル管理」で「PKI 証明書」を選択します:

![](/files/a3147d365579843be2f9b1d59aeca59ac0b9f0ac)

「管理証明書テンプレート」「外部 CA」タブに切り替えて編集モードを有効にしてください。構成プロファイル用の「SCEP Proxy」を Jamf Pro で有効にしてください:

![](/files/74b991af8bce45b6f5bc70cb18c58b38d84bfa6d)

次の項目を入力して、設定を保存してください:

| 項目            | 説明                                                                                    | 例/値                                                                                                                                                        |
| ------------- | ------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **URL**       | <p>SCEPman への URL</p><p>実行する <strong>しない</strong> 忘れずに <strong>/jamf</strong> 末尾に</p> | <https://scepman.contoso.com/jamf>                                                                                                                         |
| **名前**        | インスタンス名                                                                               | SCEPman Contoso                                                                                                                                            |
| **サブジェクト**    | X.500 標準に従うエンティティ                                                                     | O=Contoso                                                                                                                                                  |
| **チャレンジ タイプ** | 証明書発行を検証するためのチャレンジ タイプ                                                                | Static                                                                                                                                                     |
| **（検証）チャレンジ** | 事前共有シークレット（チャレンジ）                                                                     | SCEPman で次の方法により定義されます: [AppConfig](/ja/scepman-no/application-settings/scep-endpoints/jamf-validation.md#appconfig-jamfvalidation-requestpassword) パラメーター |
| キー サイズ        | ビット単位のキー サイズ                                                                          | 2048                                                                                                                                                       |
| デジタル署名として使用   |                                                                                       | はい（必要に応じて）                                                                                                                                                 |
| 鍵暗号化に使用       |                                                                                       | はい（必要に応じて）                                                                                                                                                 |
| フィンガープリント     | SCEPman CA 証明書のサムプリント（SHA-1）                                                          | SCEPman ダッシュボード（「CA サムプリント」）で確認できます                                                                                                                        |

![](/files/1c713b97fe813ae11b79cbbb246b2d3dd601affe)

### 署名証明書

外部 CA を使用する場合、Jamf は CA 証明書を追加して、証明書が正しく署名されているか比較できるようにすることを要求します。ただし、Jamf では、対応する秘密鍵を持つ署名証明書も追加した場合にのみ CA 証明書を追加できます。Jamf はこの署名証明書を使用して、SCEPman に送信される証明書要求に署名します。ただし、SCEPman は要求の署名を検証せず、要求の正当性は Jamf で構成された正しい要求チャレンジパスワードを使用していることのみに基づくため、署名されていない要求（たとえば Intune からの要求）であっても受け入れます。

{% tabs %}
{% tab title="OpenSSL" %}

```shellscript
openssl req -x509 -newkey rsa:4096 -keyout tempKey.key -out tempCert.pem -sha256 -days 3650 -nodes -subj "/CN=JAMF Signer Certificate for SCEPman"
openssl pkcs12 -export -out SigningCert.pfx -inkey ./tempKey.key -in ./tempCert.pem -passout pass:password
# 一時ファイルを削除
rm tempKey.key
rm tempCert.pem
```

{% endtab %}

{% tab title="PowerShell" %}

```powershell
$cert = New-SelfSignedCertificate -Subject "CN=JAMF Signer Certificate for SCEPman" -CertStoreLocation "Cert:\\CurrentUser\\My" -NotAfter (Get-Date).AddYears(10)
$pfxBytes = $cert.Export([System.Security.Cryptography.X509Certificates.X509ContentType]::Pfx, "password")
[System.IO.File]::WriteAllBytes("c:\\temp\\jamf.pfx", $pfxBytes)
```

{% endtab %}
{% endtabs %}

その後、Jamf の外部 CA 設定で「署名証明書と CA 証明書の変更」をクリックします

![](/files/16fdfbed224ee7aac678aad146bf829f9b5cc6e9)

ウィザードでは、求められたら署名証明書を含む PFX ファイルを Jamf にアップロードします（注: Pkcs#12 と PFX は同義です）。次の手順で、PFX ファイルのパスワードを入力し、署名証明書の選択を確認します。「CA 証明書のアップロード」タブでは、SCEPman CA 証明書をアップロードする必要があります。SCEPman CA 証明書は、SCEPman インスタンスのホームページ右上にある「CA 証明書を取得」リンクをクリックして取得できます。最後に、変更を確定します。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/jamf/general.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
