RUCKUS provides functionality for certificate enrollment through the use of the Simple Certificate
Enrollment Protocol (SCEP). Certificate enrollment is an essential PKI operation in
which a system requester successfully receives a certificate from the Certificate
Authority (CA).
SCEP is designed to support the following PKI operations:
Certificate Authority (CA) public key distribution
Registration Authority (RA) public key distribution
In FIPS mode, CRL-related commands are blocked. When a user tries to configure a CRL-related
command, a message is logged to indicate that the command is not supported in FIPS
mode. There are two basic modes: manual enrollment and automatic enrollment.
Communications between requesters and the CA are made secure using SCEP Secure Message
Objects, which specifies how the PKCS #7 cryptographic message syntax is used to encrypt
and sign the data. To ensure that the signing operation can be completed, the client
uses an appropriate (valid) local certificate.