> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/static-certificates/google-workspace/chromeos.md).

# ChromeOS

## ルート証明書

最初の手順として、SCEPman のルート証明書を展開する必要があります。したがって、次の手順に従ってください:

1. SCEPman の Web サイトからルート CA 証明書をダウンロードするには、次をクリックします **CA 証明書を取得** リンク。

<figure><img src="/files/5b7acc7d11cb734db7f645f8f6c32d8f9ef297ff" alt=""><figcaption></figcaption></figure>

2. 今、SCEPman のルート CA を Google Workplace にアップロードします。Google **管理コンソール** (admin.google.com) で次へ移動します **メニュー** > **デバイス** > **ネットワーク** > **証明書** > **証明書を追加**

{% hint style="warning" %}
Google 管理コンソールは PEM 形式の証明書のみを受け入れることに注意してください。SCEPman ルート CA（既定では DER でダウンロードされます）を次の方法で変換する必要があります。 *openssl* または、Windows にインポートしてから Base-64 形式で再度エクスポートします。
{% endhint %}

<figure><img src="/files/6f3e8499027ef42c466833f051ddd8583f549aec" alt=""><figcaption></figcaption></figure>

## SCEP プロファイルを追加

SCEP プロファイルは、ユーザーが WiFi にアクセスできるようにする証明書を定義します。組織部門に追加することで、特定のユーザーにプロファイルを割り当てます。デバイスの種類ごとにアクセスを管理するため、複数の SCEP プロファイルを設定します。次の構成例

1. Google の **管理コンソール** (admin.google.com) で次へ移動します **メニュー** > **デバイス** > **ネットワーク**
2. クリック **SCEP プロファイルを作成**.
3. クリック **Secure SCEP プロファイルを追加**.
4. プロファイルの構成詳細を入力します。

| 属性                | 値（デバイス）          | 値（ユーザー）          |
| ----------------- | ---------------- | ---------------- |
| **デバイス プラットフォーム** | Chromebook（デバイス） | Chromebook（ユーザー） |

<figure><img src="/files/d9afb6a2ef1bb7efc004443f0a012a46b362a80c" alt=""><figcaption></figcaption></figure>

| 属性               |                       |
| ---------------- | --------------------- |
| **SCEP プロファイル名** | SCEP プロファイルの名前を指定します。 |

<figure><img src="/files/4857126536ad9e9b78ab7df9e599e504d8ec1d40" alt=""><figcaption></figcaption></figure>

<table><thead><tr><th width="246">属性</th><th width="282">値（デバイス）</th><th>値（ユーザー）</th></tr></thead><tbody><tr><td><strong>サブジェクト名の形式</strong></td><td><strong>完全識別名</strong></td><td><strong>完全識別名</strong></td></tr><tr><td></td><td><strong>コモン ネーム</strong>: ${DEVICE_SERIAL_NUMBER}</td><td><strong>コモン ネーム:</strong> ${USER_EMAIL}</td></tr><tr><td></td><td><strong>会社名</strong>: 会社名を指定します。</td><td><strong>会社名</strong>: 会社名を指定します。</td></tr><tr><td></td><td><strong>組織部門:</strong> 組織部門です。これは省略可能です。</td><td><strong>組織部門:</strong> 組織部門です。これは省略可能です。</td></tr><tr><td></td><td><strong>市区町村</strong>: 組織部門の所在地です。これは省略可能です。</td><td><strong>市区町村</strong>: 組織部門の所在地です。これは省略可能です。</td></tr><tr><td></td><td><strong>都道府県</strong>: 組織部門の州です。これは省略可能です。</td><td><strong>都道府県</strong>: 組織部門の州です。これは省略可能です。</td></tr><tr><td></td><td><strong>国 / 地域</strong>: 組織部門の国です。これは省略可能です。</td><td><strong>国 / 地域</strong>: 組織部門の国です。これは省略可能です。</td></tr><tr><td><strong>サブジェクト代替名</strong></td><td>デフォルト: <strong>なし</strong><br><br>これは次のように設定できます <strong>カスタム</strong> SAN を使用する場合、たとえば EAP-TLS を使用して WiFi に認証するときの外部 ID として設定します。</td><td><p><strong>カスタム</strong></p><p><strong>ユーザー プリンシパル:</strong> ${USER_EMAIL_NAME}</p></td></tr><tr><td></td><td></td><td></td></tr></tbody></table>

<figure><img src="/files/189e5962335b8193b820b59ee055b80af6ad585d" alt=""><figcaption></figcaption></figure>

| 属性            | Value            |
| ------------- | ---------------- |
| **署名アルゴリズム**  | SHA256withRSA    |
| **キー使用法**     | キーの暗号化、署名        |
| **鍵サイズ（ビット）** | 3072             |
| **セキュリティ**    | 厳密（管理対象デバイスのみ対応） |

<figure><img src="/files/69f8a66d0fe36df6ca6dc40650eb41c78e49d079" alt=""><figcaption></figcaption></figure>

<table><thead><tr><th width="246">属性</th><th>Value</th></tr></thead><tbody><tr><td><strong>SCEP サーバー属性</strong></td><td><strong>SCEP サーバー URL</strong>: <a href="http://scepman.yourdomain.net/static">http://scepman.yourdomain.net/static</a></td></tr><tr><td></td><td><strong>証明書の有効期間（年）</strong>: 1</td></tr><tr><td></td><td><strong>次の期間内に更新</strong>: 42</td></tr><tr><td></td><td><strong>拡張キー使用法</strong>: クライアント認証</td></tr><tr><td></td><td><strong>チャレンジの種類</strong>: 固定</td></tr><tr><td></td><td><strong>チャレンジ</strong>: 有効化するときに構成したチャレンジ値を指定します <a href="/pages/525f222e0d3ed830e67891d9099d0560ef100394#enable-google-workspace-integration">SCEPman Google Workspace</a> 統合。</td></tr><tr><td></td><td><strong>認証局</strong>: ここでは、次を含む証明書プロファイルを参照します <a href="#root-certificate">SCEPman ルート CA</a>.</td></tr><tr><td></td><td><strong>このプロファイルが適用されるネットワークの種類</strong>: Wi-Fi</td></tr></tbody></table>

<figure><img src="/files/b5aa22231b49896d3621be4a04a6d73e17e0b2c9" alt=""><figcaption></figcaption></figure>

5. SCEP プロファイルは、組織部門内のユーザーに自動的に配布されます。
6. この証明書を確認するには、Chromebook で次へ移動します **chrome://certificate.manager** > **証明書。**

<figure><img src="/files/8c650f9fe22b57132b2a3af4322594eb022ed60f" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/static-certificates/google-workspace/chromeos.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
