Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tedauction
New Contributor III

Fortiauthenticator SCEP with MDM ?

Hello, we are trying to get SCEP certificate enrollment working between FortiAuthenticator and Google MDM (mobile device management).

We will push out a Google MDM wifi profile to all mobile devices requesting a SCEP certificate from FortiAuthenticator. It is not working for us and there is very little (if any) documentation on this.

Has anyone got FAC SCEP working with an MDM of any kind ?

Thank you kindly.

2 REPLIES 2
xsilver_FTNT
Staff
Staff

Hi,

not sure how it should be specific for MDM, but on FAC it should be as any other SCEP cert enrollment.

So components and config like SCEP template are supposed to be same.

Logging section should be helpful, also you can sniff CSRs sent to FAC as SCEP is supposed to be HTTP traffic by default. So have a look if you even received CSR on FAC and if the request did match to any enrollment template.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

shikhakolekar

Hello, 

 

Having this updated so it can help others as well. 

You can have the SCEP added as per document https://docs.fortinet.com/document/fortiauthenticator/8.0.0/administration-guide/527816/scep, logs can be checked by navigating on https://facserver/debug  >> Others >> SCEP/CMP. A packet capture as well helps. 

 

If you have found a solution, please like and accept it to make it easily accessible for others.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors