none
Windows MDM bulk enrollment flow - Key usage not coming as a part of CSR RRS feed

  • Question

  • Hi All,

    We are trying for bulk enrollment work flow in case windows 10 MDM desktop devices.

    Below are the steps we are following.

    1)windows 10 MDM Device requests for SCEP policy from Server.

    2) Server issues SCEP policy which has key usage property set as below.

    <privateKeyAttributes>
    <minimalKeyLength>2048</minimalKeyLength>
    <keySpec xsi:nil=\"true\"/>
    <permissions xsi:nil=\"true\"/>
    <algorithmOIDReference>1</algorithmOIDReference>
    <cryptoProviders xsi:nil=\"true\"/>
    <keyUsageProperty>5<keyUsageProperty>
    </privateKeyAttributes>

    3) server provides certificates to the windows 10 devices after receiving the CSR from the devices.

    However CSR is not having key usage parameters set even server has provided the SCEP policy.

    4) We have also tried passing Extended key usage in SCEP policy. That also didn't help.

    Question:

    Can we get any information on why the "Keyusage" property is not set in CSR? Do we need to set any additional attributes also in SCEP policy? Any suggestions would be of great help.

    Thanks

    Fijo.

    Wednesday, April 10, 2019 5:53 AM