<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pki on Network Haven</title>
    <link>/tags/pki/</link>
    <description>Recent content in Pki on Network Haven</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 13 May 2026 12:00:00 +0200</lastBuildDate>
    <atom:link href="/tags/pki/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Fixing SCEP Certificate Enrollment over HTTPS on eLux Thin Clients</title>
      <link>/posts/2026/fixing-scep-certificate-enrollement-over-https-on-elux-thin-clients/</link>
      <pubDate>Wed, 13 May 2026 12:00:00 +0200</pubDate>
      <guid>/posts/2026/fixing-scep-certificate-enrollement-over-https-on-elux-thin-clients/</guid>
      <description>&lt;p&gt;Currently we trying out eLux as an replacement of older thin clients with ThinOS or IgelOS. We tried to configure 802.1x authentication and the therefore needed certificate enrollment with our current SCEP/NDES server. We came across the issue that the scep client that eLux uses – &lt;a href=&#34;https://github.com/certnanny/sscep&#34;&gt;sscep&lt;/a&gt; – an open source “Simple SCEP client for Unix” &lt;strong&gt;doesn’t support certificates requests over HTTPS&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;When investigating the problem we found this GitHub issue which explains our problem. Our NDES server was only reachable over HTTPS – both on the administration page and most importantly also on the request web page (certsrv/mscep) where the client requests their certificates.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
