إنتقل إلى المحتوى الرئيسي
ينطبق على:
DuoKey Cockpit v2Microsoft AD CS via NDESSCEP (RFC 8894) enrollment

Overview​

Microsoft AD CS (NDES) is registered as an issuer type in Cockpit's PKI module. The connector acts as a SCEP client (RFC 8894) against a Network Device Enrollment Service endpoint — the standard way non-domain-joined and network devices enroll against Active Directory Certificate Services.

AD CS (NDES) connector architecture
DuoKey CockpitPKI issuer connector — AD CS (NDES)
SCEP (RFC 8894) — challenge password embedded in the request
Network Device Enrollment ServiceSCEP front end for Active Directory Certificate Services
AD CS issuing CASigns the certificate

NDES is the SCEP front end that forwards enrollment requests into Active Directory Certificate Services.

PropertyValue
Issuer typeadcs-ndes
BackendActive Directory Certificate Services, via NDES (SCEP, RFC 8894)
AuthenticationNDES challenge password, embedded in the SCEP request
Key algorithmRSA only — required by SCEP's key-transport mechanism
Key generationBy the connector itself, not by the caller
RevocationNot supported — SCEP has no revoke operation
No revoke operation

SCEP (RFC 8894) does not define a certificate revocation operation, so the AD CS (NDES) connector's revoke always fails with a clear error. To revoke a certificate issued through this connector, revoke it directly on the certification authority — the AD CS console or certutil -revoke — not through Cockpit. Plan your revocation process accordingly before relying on this issuer for certificates that may need to be revoked.

Why the connector generates the key pair​

SCEP's enrollment protocol embeds the challenge password inside the signed certificate request, and the server's response is encrypted back to the requester's key. Because of this, a certificate signing request supplied by the caller cannot participate — Cockpit does not hold the matching private key and cannot inject the challenge password into an already-signed request.

For this reason, the AD CS (NDES) connector generates the RSA key pair itself at issuance time and rejects any request that already carries a CSR. The private key is returned once, alongside the issued certificate — the same pattern used for DuoKey's internal CA managed-key issuance. Capture and store it at issuance time; it is not retrievable afterwards.

SCEP enrollment flow
1. Discover capabilitiesServer capabilities — supported algorithms, POST support
2. Fetch the CA certificateOptionally pinned by SHA-256 fingerprint
3. Generate the key pairConnector-generated RSA key pair and CSR, with the challenge password embedded — no caller-supplied CSR
signed, encrypted enrollment request
4. Submit for enrollmentNDES validates the challenge password and forwards it into AD CS
5a. IssuedCertificate and private key returned together, once
5b. Pending approvalPolled briefly; still pending after that needs manual approval on the CA, then a fresh request

The connector — not the caller — holds the private key throughout, because the challenge password must be embedded in the signed request and the server's response is encrypted back to that same key. SCEP defines no revoke operation, so there is no step for it here.

Configuration​

Config fields​

FieldPurpose
scep_urlThe NDES SCEP endpoint URL.
ca_fingerprint_sha256Optional SHA-256 fingerprint used to pin the expected CA certificate — enrollment is refused if the CA certificate returned by the server does not match.
key_sizeRSA key size for the generated enrollment key pair. Defaults to 2048 bits.

Credentials​

FieldPurpose
challenge_passwordThe static NDES enrollment challenge password. A per-enrollment challenge can also be supplied on individual issuance requests.

The challenge password is encrypted at rest and never echoed back by the platform.

Enterprise networks

The SCEP URL commonly points at a host on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.

Registering the issuer​

1

Provide the SCEP endpoint

Enter the NDES SCEP endpoint URL for your AD CS deployment.

2

Provide the challenge password

Enter the NDES enrollment challenge password. Pin the expected CA certificate by SHA-256 fingerprint if desired.

3

Set the key size

Confirm the RSA key size for connector-generated enrollment keys (default 2048 bits).

4

Test the connection

Run test-connection to confirm the SCEP endpoint is reachable and to review its advertised capabilities and CA certificate(s).

5

Issue through the issuer

Request certificates against the issuer. Do not supply a CSR — the connector generates the RSA key pair and CSR itself, embedding the challenge password.

Supported operations​

OperationSupportedNotes
test-connectionYesQueries CA capabilities and CA certificate(s) over SCEP.
issueYesGenerates the RSA key pair, embeds the challenge password in the CSR, and completes the SCEP PKCSReq/CertRep exchange.
renewYesNo native renewal flow — renew generates a fresh key pair and re-enrolls.
revokeNoSCEP has no revoke operation. Revoke on the certification authority itself.
Manual-approval CAs

If the NDES/CA policy holds enrollment requests for manual approval, issuance does not complete automatically: Cockpit polls briefly for the certificate and, if it is still pending after that window, returns an error asking you to approve the request on the CA and issue again. SCEP's polling token is not persisted across requests, so a request left pending cannot be completed automatically later — configure automatic issuance via the challenge password where possible.