Renewing SCEPman Root CA
Last updated
Was this helpful?
Last updated
Was this helpful?
The SCEPman Root CA is valid for 10 years. Once it has expired, SCEPman will need to be re-deployed, as there is currently no method to extend the validity period past 10 years or to renew the existing Root CA.
A redeployment has the advantage that the new Root CA will live up to the security standards (key size, algorithms etc.) that are relevant to that time in the future.
The second instance should be set up identically to your primary instance or in a way that's ready to use.
This may include:
Additional MDM Configurations
Health Checks
Environment Variables
Custom Domains and Geo-redundancy (Save this until after the cutover if you plan to re-use the existing custom domain)
Update Strategy
Only begin this step once all endpoint devices have received Root and SCEP certificates from the secondary instance.
MDMs configuration profiles should now point to the Secondary SCEPman instance for cases such as WiFi authentication.
Custom Domain and Geo-Redundancy should be set up now if you are re-using your initial custom domain.
Make adjustments on systems/applications as necessary.