Microsoft AD CS (NDES)
SCEP enrollment against Active Directory Certificate Services through the Network Device Enrollment Service.
Overview
Microsoft AD CS (NDES) is registered as an issuer type in Cockpit's PKI module. The connector acts as a SCEP client (RFC 8894) against a Network Device Enrollment Service endpoint — the standard way non-domain-joined and network devices enroll against Active Directory Certificate Services.
NDES is the SCEP front end that forwards enrollment requests into Active Directory Certificate Services.
| Property | Value |
|---|---|
| Issuer type | adcs-ndes |
| Backend | Active Directory Certificate Services, via NDES (SCEP, RFC 8894) |
| Authentication | NDES challenge password, embedded in the SCEP request |
| Key algorithm | RSA only — required by SCEP's key-transport mechanism |
| Key generation | By the connector itself, not by the caller |
| Revocation | Not supported — SCEP has no revoke operation |
SCEP (RFC 8894) does not define a certificate revocation operation, so the AD CS (NDES) connector's revoke always fails with a clear error. To revoke a certificate issued through this connector, revoke it directly on the certification authority — the AD CS console or certutil -revoke — not through Cockpit. Plan your revocation process accordingly before relying on this issuer for certificates that may need to be revoked.
Why the connector generates the key pair
SCEP's enrollment protocol embeds the challenge password inside the signed certificate request, and the server's response is encrypted back to the requester's key. Because of this, a certificate signing request supplied by the caller cannot participate — Cockpit does not hold the matching private key and cannot inject the challenge password into an already-signed request.
For this reason, the AD CS (NDES) connector generates the RSA key pair itself at issuance time and rejects any request that already carries a CSR. The private key is returned once, alongside the issued certificate — the same pattern used for DuoKey's internal CA managed-key issuance. Capture and store it at issuance time; it is not retrievable afterwards.
The connector — not the caller — holds the private key throughout, because the challenge password must be embedded in the signed request and the server's response is encrypted back to that same key. SCEP defines no revoke operation, so there is no step for it here.
Configuration
Config fields
| Field | Purpose |
|---|---|
scep_url | The NDES SCEP endpoint URL. |
ca_fingerprint_sha256 | Optional SHA-256 fingerprint used to pin the expected CA certificate — enrollment is refused if the CA certificate returned by the server does not match. |
key_size | RSA key size for the generated enrollment key pair. Defaults to 2048 bits. |
Credentials
| Field | Purpose |
|---|---|
challenge_password | The static NDES enrollment challenge password. A per-enrollment challenge can also be supplied on individual issuance requests. |
The challenge password is encrypted at rest and never echoed back by the platform.
The SCEP URL commonly points at a host on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.
Registering the issuer
Provide the SCEP endpoint
Enter the NDES SCEP endpoint URL for your AD CS deployment.
Provide the challenge password
Enter the NDES enrollment challenge password. Pin the expected CA certificate by SHA-256 fingerprint if desired.
Set the key size
Confirm the RSA key size for connector-generated enrollment keys (default 2048 bits).
Test the connection
Run test-connection to confirm the SCEP endpoint is reachable and to review its advertised capabilities and CA certificate(s).
Issue through the issuer
Request certificates against the issuer. Do not supply a CSR — the connector generates the RSA key pair and CSR itself, embedding the challenge password.
Supported operations
| Operation | Supported | Notes |
|---|---|---|
| test-connection | Yes | Queries CA capabilities and CA certificate(s) over SCEP. |
| issue | Yes | Generates the RSA key pair, embeds the challenge password in the CSR, and completes the SCEP PKCSReq/CertRep exchange. |
| renew | Yes | No native renewal flow — renew generates a fresh key pair and re-enrolls. |
| revoke | No | SCEP has no revoke operation. Revoke on the certification authority itself. |
If the NDES/CA policy holds enrollment requests for manual approval, issuance does not complete automatically: Cockpit polls briefly for the certificate and, if it is still pending after that window, returns an error asking you to approve the request on the CA and issue again. SCEP's polling token is not persisted across requests, so a request left pending cannot be completed automatically later — configure automatic issuance via the challenge password where possible.