Microsoft CA - SCEP

Hi,

I’m trying to use SCEP to import a certificate from a Microsoft CA, the certificate will be used for EAP-TLS. I’m struggling to understand the process and have some concerns that it might not work due to some known issues that I’ve read on the forum. Here’s what I’ve tried so far:

  1. Copied then installed the root and issuing CA certificates to Mikrotik device (the device doesn’t recognize the cert as a CA cert for some reason)
  2. Created a certificate template (I’ve not signed it, does SCEP take care of that?)
  3. Created a certificate request using template and challenge passphrase provided by MS CA
  4. Added a SCEP-RA referencing the MS CA server and the template and hit apply

When debugging the certificate process on Mikrotik I see that it receives two certificates from the MS CA then it fails and shortly after.

Has anyone gotten this process working with MS CA, could you kindly share any processes, or highlight where I have made a mistake above.

Thanks
Pete.

Looking for the same

No luck in that thread: http://forum.mikrotik.com/t/scep-client-wont-work-with-ms-ca-server/105556/1

Thanks

sebus

Anybody?

sebus

Hmm, might have to spin up a MS CA to see how this works.