<key>SubjectAltName</key>
<dict>
<key>uniformResourceIdentifier</key>
<array>
<string>deviceid://%HardwareUUID%</string>
</array>
</dict>
Note: Smallstep needs to change the challenge time from 1 minute to 1 hour to match our NDES behavior/expectations.
customer-reedtimmer: https://us-65885.app.gong.io/call?id=3444438867398665141&highlights=%5B%7B%22type%22%3A%22SHARE%22%2C%22from%22%3A3266%2C%22to%22%3A3363%7D%5Dreedtimmercustomer promise.Gong snippet for call with Smallstep: https://docs.google.com/document/d/1CdxvU61kMqyH_B51kbGnn5HVDoUTZPxGYzftgsIrNpU/edit?tab=t.0#heading=h.7en766pueek4
@noahtalerman: User requested this because they want to deploy a SCEP certificate from Smallstep with dynamic challenge to connect their end users to Wi-Fi or VPN.
$FLEET_VAR_NDES_SCEP_CHALLENGEas the challenge so that Fleet uses a dynamic challenge (guide here).@getvictor: Was able to get a cert onto macOS using our example NDES SCEP profile with the following addition:
Note: Smallstep needs to change the challenge time from 1 minute to 1 hour to match our NDES behavior/expectations.