Enhanced SAN Handling for SCEP Certificates

To provide an overview of a feature and its benefits. May require several Concept topics to keep content in short, manageable, and reusable chunks of content.

The intention of this new template is to outline the information that you will need to collect from SMEs and provide to readers.

NOTE: Feature Configuration / Troubleshooting are *not* part of the Feature Concept template. These templates are likely to be part of seperate task/reference templates (to be developed).

General Notes for Concept Topics:
  • Optional sections are to be used with discretion based on the feature characteristics.

Feature Overview

When generating certificates using the Simple Certificate Enrollment Protocol (SCEP), the system captures and utilizes Subject Alternative Name (SAN) values from the Certificate Signing Request (CSR). This helps Cloudpath to effectively leverage SAN attributes for certificate creation and authentication processes.

This feature enhances SCEP certificate generation by allowing for the pass-through of SAN values from the CSR. When Microsoft Entra or Intune is selected as the SCEP key, a new checkbox is introduced to control how SAN values are handled. The system captures and preserves SAN values from the CSR during the certificate generation process.

The checkbox, Use SAN values from request, is available within SCEP settings to enable or disable SAN value utilization.

The following SAN types are supported:

  • Other Name (UPN)
  • RFC822 (email)
  • DNS Name
  • URL/URI

The process for configuring Intune and Cloudpath includes:

By effectively managing SAN values during the SCEP certificate generation process, this feature empowers organizations to optimize certificate utilization and strengthen overall security.

This section is required. Providing detailed and accurate information in the feature overview is crucial as it helps users understand the functionality, benefits, and usage of the feature. Moreover, it ensures consistency in communication across all platforms, enhancing user experience and product perception.
  • What is the name of the feature? (What do users call the feature? If the feature is referred to by an acronym, what is the acronym expansion? What is the formal name to be used in documentation?)
    Note: Typically, the name is used as part of the section titles, such as the overview title and the configuration section titles.
  • Where does the feature fit within our taxonomy? (What are the taxonomy group and sub-group? This information is important for categorizing the feature documentation and incorporating it into the existing document sets.)
  • What standard or standards govern the feature? (Sometimes needed.)
  • Is the feature a new feature or an enhancement to an existing feature?
  • Does the feature replace another feature?
  • What does the feature do? (General description)
  • How does the feature benefit the user?
  • What set of terms do the writer and reader need to know to understand the feature and its use?
  • How does the feature work? (Detailed description, if needed.)

Requirements

This feature has no special hardware or software requirements for feature enablement or usage.

This section is required. Including this section, even when there is no impact, lets SMEs and customers know that the associated information was not forgotten.

If there are no requirements, use the following default wording:

This feature has no special hardware or software requirements for feature enablement or usage.

If there are requirements, include the applicable below points (depending on product line):

  • What releases support the feature?
    Note: Typically, this is not documented in the configuration guides; however, we need to know where to include the information.
  • What hardware models support the feature?
  • Does the feature require specific modules?
  • Does the feature run only on certain ports?
  • Does the feature have special memory requirements?
  • In an integrated system, can the feature be managed or configured from another device? What are the related release and system requirements?
  • Does the feature introduce new user requirements?
  • Does the feature introduce physical or location-based requirements?

Considerations

This feature has no special considerations or limitations pertaining to feature enablement or usage.

This section is required. Including this section, even when there is no impact, lets SMEs and customers know that the associated information was not forgotten.

If there are no considerations, use the following default wording:

This feature has no special considerations or limitations pertaining to feature enablement or usage.

If there are considerations, include the applicable below points (depending on product line).

Note: A separate section on Limitations may sometimes be needed.
  • Does the feature replace an existing feature?
  • Does the feature work only with a certain protocol or with a limited set of protocols?
  • Is the feature meant to be used in combination with another feature or a set of features?
  • Is the feature incompatible with any features?
  • What happens when the feature is enabled?
  • What happens when the feature is disabled?
  • Does enabling/disabling the feature enable/disable another feature?
  • What system behavior changes, if any, does the feature introduce?
  • Are performance issues associated with the feature? How can these be mitigated?

Best Practices

  • Use SAN attributes for certificate creation and authentication.
  • Employ the device ID from Intune for authentication purposes.
  • Use the Common Name (CN) as the user ID for eduroam.
.
This section is required. Including this section, even when there is no impact, lets SMEs and customers know that the associated information was not forgotten.

If there are no best practices (recommendations), use the following default wording:

This feature has no special recommendations for feature enablement or usage.

If there are considerations, include the applicable below points (depending on product line).

  • Brief list of RUCKUS recommendations on product use to optimize performance.

Prerequisites

To use this feature, you need a Microsoft Entra ID or Intune account to access the appropriate application.

Following are the links to the Microsoft 365 Developer program and Intune:

This section is required. Including this section, even when there is no impact, lets SMEs and customers know that the associated information was not forgotten.

If there are no prerequisites, use the following default wording:

This feature has no prerequisites to feature enablement or usage.

If there are prerequisites, include the applicable below points (depending on product line).

Note: This section is sometimes part of a general overview and sometimes part of a configuration overview.
  • What are the task prerequisites that the user must ensure are met,for configuration? (For example, must you be running certain protocols, or must you configure other features first?)