> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/static-certificates/kandji-1.md).

# Iru (formerly Kandji)

SCEPman を External CA として接続することで、Iru で証明書を発行します。デバイスは、SCEPman の静的インターフェースと登録済みのチャレンジ パスワードを使用して証明書を取得できます。

SCEPman は接続できます [Iru](https://www.iru.com/) SCEPman の静的インターフェースとチャレンジパスワードを使用して外部 CA として利用し、登録済みデバイスが証明書を取得できるようにします。

他の MDM ソリューションと SCEPman 連携に関するより一般的な情報については、次をご確認ください [こちら](/ja/zheng-ming-shu-guan-li/static-certificates.md).

## Iru 連携を有効にする

SCEPman App Service 上の次の環境変数を使用すると、SCEPman の連携を簡単に有効化できます:

{% hint style="info" %}
SCEPman App Service と Certificate Master は、App Service を見ることで区別できます **なしで** 名前にある「-cm」
{% endhint %}

|                                                                                                設定                                                                                               | 説明                                                                                                                                                                                                                              |                    値                    |
| :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------: |
|                     [AppConfig:StaticValidation:Enabled](/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enabled)                     | サードパーティ検証を有効にする                                                                                                                                                                                                                 | ***true*** 有効にするには、 ***false*** 無効にするには |
|             [AppConfig:StaticValidation:RequestPassword](/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword)             | <p>署名のために SCEPman に送信される証明書署名要求は、この安全な静的パスワードで認証されます<br><br><strong>推奨</strong>: このシークレットは次の場所に保存してください <a href="/ja/scepman-gou-cheng/application-settings.md#secure-configuration-in-azure-key-vault">Azure KeyVault</a>.</p> |            *32 文字のパスワードを生成する*           |
|       [AppConfig:StaticValidation:ValidityPeriodDays](/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-validityperioddays) （省略可）       | Iru 経由で発行された証明書の有効日数                                                                                                                                                                                                            |                   365                   |
| [AppConfig:StaticValidation:EnableCertificateStorage](/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enablecertificatestorage) （省略可） | 要求された証明書を Storage Account に保存し、SCEPman Certificate Master に表示できるようにします                                                                                                                                                          | ***true*** 有効にするには、 ***false** 無効にするには* |

{% hint style="warning" %}
SCEPman の構成パラメーターを追加または編集した後は、App Service を再起動する必要があります。
{% endhint %}

## Iru の構成

### SCEPman ルート証明書

最初の手順として、SCEPman のルート証明書を展開する必要があります。この CA 証明書は SCEPman の Web サイトからダウンロードしてください:

![SCEPman Web サイト](https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9170eb0435726398eb43f6fac8abd0d5f35e8cc4%2FSCEPmanHomePage%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(2\).png?alt=media)

Iru で **ライブラリ** 左側のナビゲーション バーで次を追加します **証明書ライブラリ項目** を Blueprint に追加します。

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FfToUgpoUeZOiYNe2xkzi%2F2023-03-09%2012_51_21-Window.png?alt=media&amp;token=df6f66fb-369b-4adf-ab9d-70757354f2f7" alt=""><figcaption><p>証明書ペイロードを構成する</p></figcaption></figure>

証明書をアップロードするには、まず次を選択します **PKCS #1 形式の証明書** 次の下に **証明書の種類**、次に任意の名前を指定し、SCEPman CA 証明書をアップロードして、最後に保存します。

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FL8NyfsJR7x2v0j6ybS6g%2F2023-03-09%2014_21_12-KandjiSCEPmanRootCA.png?alt=media&amp;token=a70ff955-bbe2-4b49-9cf4-245964838675" alt=""><figcaption><p>SCEPman ルート CA 証明書の追加</p></figcaption></figure>

### SCEP プロファイル

次の手順は、 **SCEP プロファイル** をあなたの **ブループリント**。そのため、新しい **SCEP ライブラリアイテム** を追加し、以下のように構成します:

* **URL**: 構成した SCEPman の静的 SCEP エンドポイント [上記](#enable-kandji-integration)
* **名前:** 任意の SAN 属性
* **チャレンジ**: SCEPman の静的 SCEP インターフェースに送信される CSR 要求を認証するために必要です。次と一致している必要があります [値](/ja/scepman-gou-cheng/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword) 構成した [上記](#enable-kandji-integration).
* **フィンガープリント:** 任意の CA フィンガープリント。この値を構成することを強く推奨します。追加のセキュリティ層が提供されるためです。SCEPman の Web サイトでは次の名前で見つけられます **CA サムプリント**.
* **サブジェクト:** 任意のサブジェクト名。 **CN=$PROFILE\_UUID** は、Iru から既定の共通名として自動的に追加されます。Iru では複数の CN を追加できます。

{% hint style="warning" %}
CN を 2 つを超えて追加すると、macOS と iOS でネットワーク認証目的のクライアント証明書を自動選択できないことがありました。
{% endhint %}

* **キー サイズ:** 2048
* **キーの使用法:** 署名と暗号化の両方

詳細については、次をご確認ください [Iru のドキュメント](https://support.kandji.io/support/solutions/articles/72000559782-scep-profile).

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FS84P4c40cLu5H5NCeley%2F2023-03-09%2014_43_19-Kandji.png?alt=media&amp;token=45fdf5b6-6a31-4879-ba87-a7070e76e0c5" alt=""><figcaption><p>SCEP プロファイルの追加</p></figcaption></figure>

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FhnTLPcfOXlMpBNOh5Nph%2F2023-03-09%2014_50_23-Kandji.png?alt=media&amp;token=1ed96cb6-861a-4cb7-8511-22e1b0b48763" alt=""><figcaption><p>SCEP プロファイルの構成</p></figcaption></figure>

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FbZiDYnqsvxgh8a36zPl3%2F2023-03-09%2014_51_22-Kandji.png?alt=media&amp;token=d2e681dd-f50d-4043-a85a-46bd7396d810" alt=""><figcaption><p>SCEP プロファイルの構成</p></figcaption></figure>

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FuiSTD2BxR4utzJ0YACZS%2F2023-03-09%2014_52_52-Kandji.png?alt=media&amp;token=84aa9c64-7b38-4829-b337-cdde8549ab98" alt=""><figcaption><p>SCEP プロファイルの構成</p></figcaption></figure>

### 展開ステータス

証明書または SCEP プロファイルを保存した後、次に切り替えます **状態** で展開ステータスを確認するには **ブループリント** 割り当てられたデバイス。

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FjchSJJzjqEDQxfX8K40s%2F2023-03-09%2015_12_40-Kandji.png?alt=media&amp;token=5b316771-d526-45cc-8ee5-dba4d751e39f" alt=""><figcaption><p>展開ステータス</p></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/static-certificates/kandji-1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
