Kaspersky Secure Mobility Management

Connecting to an NDES/SCEP server

February 26, 2024

ID 241827

Expand all | Collapse all

You can configure a connection to an NDES/SCEP server to obtain a certificate from a certificate authority (CA) using Simple Certificate Enrollment Protocol (SCEP). To do this, you need to set up a connection to the CA using SCEP and specify a certificate profile.

To add a connection to a certificate authority and specify a certificate profile:

  1. In the console tree, in the Managed devices folder, select the administration group to which the Android devices belong.
  2. In the workspace of the group, select the Policies tab.
  3. Open the policy properties window by double-clicking any column.

    Complete the following steps within 15 minutes. Otherwise, you may face an error when saving changes to the policy.

  4. In the policy Properties window, select the Device owner mode > NDES and SCEP section.
  5. In the Connection to certificate authority (CA) section, click Add.

    The Connection to certificate authority dialog appears.

  6. Specify the following settings, and then click OK:
    • Connection name
    • Protocol type
    • SCEP server URL
    • Challenge phrase type
    • Static challenge phrase

  7. In the Certificate profiles section, click Add.

    The Certificate profile dialog appears.

  8. Specify the following certificate profile settings and click OK:
    • Profile name
    • Certificate authority (CA)
    • Subject name
    • Private key length
    • Private key type
    • Renew certificate automatically
    • Renew certificate before it expires (in days)
    • Subject Alternative Names (SAN)
  9. Click Apply to save the changes you have made.

Manage connections and certificate profiles

You can later edit or remove the added connections and certificate profile.

To edit a connection or certificate profile:

  1. Select the needed connection or certificate profile in the corresponding section.
  2. Click Edit, make the required changes, and click OK.
  3. Click Apply to save the changes you have made.

After you edit the certificate profile in policy settings, the corresponding certificate on the device is deleted automatically during the next synchronization with Administration server and a new certificate is installed.

To remove a connection or certificate profile:

  1. Select the needed connection or certificate profile in the corresponding section.
  2. Click Delete, and then click OK.

    If you remove a certificate authority connection, all certificate profiles that use this connection are also removed.

  3. Click Apply to save the changes you have made.

After you delete the certificate profile in policy settings, the corresponding certificate on the device will be deleted automatically during the next synchronization with Administration server.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.