Create a role and identity for the SCEP client
The following sections cover the password and TLS certificate authentication methods.Password authentication method
Perform the following steps to authenticate with a username and password:Create the role
Perform the following steps to create the role:On the Info tab, set the following:
| Setting | Required configuration |
|---|---|
| Type | Application |
| Name | SCEP |
| Login required | 1 |
Create the identity
Perform the following steps to create the identity:Go to Identity Management> Identities, right-click anywhere in the window, and select Add> Client Application.
On the Info tab of the Identity Editor window, select Application for the storage location, and specify SCEP as the identity name.
On the Authentication tab, remove the default API Key mechanism and select [ Add ]. In the Configure Credential dialog, select Password in the Type drop-down menu, then select [ Change ]. Set a password and select [ Save ]. Then, select [ OK ] to finish configuring the credential.
TLS authentication method
Perform the following steps to authenticate with a TLS certificate:Create the identity provider
Perform the following steps to create the identity provider:On the Info tab of the Identity Provider Editor window, specify a name for the Identity Provider and uncheck Enforce Dual Factor.
On the PKI Options tab, select [ Select ]. In the Certificate Selector window, expand the certificate tree you previously created, select the CA certificate that signed the SCEP Client and SCEP connection pair certificates, and then select [ OK ]*.
Create the role
Perform the following steps to create the role:In the Info tab of the Role Editor window, use the following settings:
| Setting | Required configuration |
|---|---|
| Type | Application |
| Name | SCEP |
| Login Required | 1 |
Create the identity
Perform the following steps to create the identity:Go to the Identity Management> Identities menu, right-click anywhere in the window, and select Add > Client Application.
On the Info tab of the Identity Editor window, select Application for the storage location and specify SCEP as the identity name.
On the Authentication tab, remove the default API Key mechanism and select [ Add ]. In the Configure Credential window, select TLS Certificate in the Type drop-down menu, then select the Provider and Mechanism you created. Select [ OK ] to finish configuring the credential.

