Are there any plans to support the RFC7030 'Enrollment over Secure Transport' for network device certificate enrollment?

B

BroH

The Network Device Enrollment Service (NDES) currently offers the Simple Certificate Enrollment Protocol (SCEP) for certificate enrollment of network devices. SCEP is a historic IETF draft with some security issues (compare Network Device Enrollment Service Guidance). The SCEP protocol is substituted by the Enrollment over Secure Transport (EST) protocol which became IETF RFC7030 in October 2013.

Is there any activity at Microsoft to offer an enrollment service for the Active Directory Certificate Service based on EST?

I'm happy for any feedback and more than happy for a timeline :)


Continue reading...
 
Back
Top Bottom