Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Intune CSR Validation for SCEP #608

Open
beejaygee opened this issue Jun 8, 2021 · 5 comments
Open

Intune CSR Validation for SCEP #608

beejaygee opened this issue Jun 8, 2021 · 5 comments
Assignees
Labels
enhancement more info needed Issue requires more information for a decision roadmap An item for roadmap discussion
Milestone

Comments

@beejaygee
Copy link

What would you like to be added

Intune CSR Validation for SCEP.

Why this is needed

This allows Intune to use SCEP for certificate deployment. This allows devices in Intune to automatically obtain a certificate for verification for 802.1x WPA Enterprise and to validate that request with Intune. This is so that enterprise MDM devices such as iPhones, Android devices, and Azure AD joined devices can enroll for certificates over the internet in a secure manner.

Now that SCEP support has been added it shouldn't be much more difficult to add Intune CSR validation. There's a few resources that Microsoft provides on the topic:

https://github.com/Microsoft/Intune-Resource-Access/tree/develop/src/CsrValidation
https://docs.microsoft.com/en-us/mem/intune/protect/scep-libraries-apis

@beejaygee beejaygee added enhancement needs triage Waiting for discussion / prioritization by team labels Jun 8, 2021
@dopey dopey added the more info needed Issue requires more information for a decision label Jun 8, 2021
@dopey dopey assigned dopey and unassigned mmalone Sep 1, 2021
@dopey dopey added roadmap An item for roadmap discussion and removed needs triage Waiting for discussion / prioritization by team labels Sep 1, 2021
@dopey
Copy link
Contributor

dopey commented Sep 1, 2021

Hey, we're interested Intune CSR validation but we don't have the bandwidth to research and plan this at the moment. More generally, we are interested in MDM, but similarly don't have the bandwidth to act on the interest right now.

For the time being I've put this issue on our roadmap so that when we discuss new projects we will address it.

@arjunasokan-bc
Copy link

Adding my +1 to this, would love to ditch Microsoft for this.

@maraino maraino added this to the Backlog milestone Aug 16, 2022
@nwmcsween
Copy link

Financially Intune support would make a lot sense for smallstep as the company I currently work for would pay for support contracts if implemented and supported.

@ccben87
Copy link

ccben87 commented Jul 21, 2023

Packetfence already has code written in Go to do this: https://github.com/inverse-inc/packetfence/blob/devel/go/caddy/pfpki/cloud/intune.go Now that SCEP has been implemented, it shouldn't be too much effort to implement this. I'm tempted to have a shot at it myself but I don't know Go and I'd be learning from scratch but don't know if I have the time.

@trs80
Copy link

trs80 commented Jul 21, 2023

Per the discord, this is apparently supported in the commercial version of smallstep

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement more info needed Issue requires more information for a decision roadmap An item for roadmap discussion
Projects
None yet
Development

No branches or pull requests

8 participants