1. Go to Network > SCEP Client (NDES) > SCEP.
  2. Enter the following data:
    • SCEP server URL: URL by which the SCEP client communicates with the SCEP server.
    On a Windows 2008 server this is http:///certsrv/mscep/mscep.dll by default.

    HTTPS is not supported; however, all security critical data that are transferred between the SCEP client and other components is encrypted.
    • Proxy server for SCEP requests (optional): IP address or host name of the proxy server that is used for the communication between device and SCEP server. If a web application firewall is used instead of a proxy, its IP address or host name of the proxy server must be entered here.
    • Challenge password: Password that the SCEP client must present to the SCEP server in its request (CSR)
    On a Microsoft NDES server, you can retrieve the password under https:///certsev/mscep_admin by default. By default, on a Microsoft NDES server, the password is valid for 1 hour, and can only be used once. For testing purposes, it might be feasible to change these settings.
    • Certificate renewal period (days): Time interval before certificate expiry after which the certificate renewal procedure is started
    • Certificate expiry check interval (days): Specifies how often the certificate is checked against its expiry date.

  3. Apply the settings by clicking Apply and send to thin client or Save.