Communications Between Requesters and the CA
The following rules apply to the communications between requesters and the CA.
-
If the requester already has a certificate issued by the SCEP server and the server supports certificate renewal, the certificate that was already issued should be used (renewed).
-
If the requester does not have a certificate issued by the new CA, but does have credentials from an alternate CA, the certificate issued by the alternate CA may be used.
-
If the requester does not have an appropriate existing certificate, then a locally generated, self-signed certificate must be used. The self-signed certificate must have the same subject name as the name used in the PKCS #10 request.