a client private key (needs to be passphrase-protected) in PEM (base64) format
Alternatively,
a PKCS#12 file containing both client certificate and private key (needs to be passphrase-protected).
In both cases, SCEP and files from UMS, the device needs to have a working Ethernet or Wi-Fi connection to the SCEP server or the UMS first, so that it can fetch the necessary certificates before it can connect to the target Wi-Fi.