Create a Simple Certificate Enrollment Protocol (SCEP) profile to automate the
generation and distribution of unique client certificates.
If you have a Simple Certificate Enrollment
Protocol (SCEP) server in your enterprise PKI, you can configure
a SCEP profile to automate the generation and distribution of unique
client certificates. SCEP operation is dynamic in that the enterprise
PKI generates a user-specific certificate when the SCEP client requests
it and sends the certificate to the SCEP client. The SCEP client
then transparently deploys the certificate to the client device.
You
can use a SCEP profile with
GlobalProtect to assign user-specific
client certificates to each GlobalProtect user. In this use case,
the GlobalProtect portal acts as a SCEP client to the SCEP server
in your enterprise PKI. Additionally, you can use a SCEP profile
to assign client certificates to
Palo Alto Networks devices for mutual authentication with
other Palo Alto Networks devices for management access and inter-device
communication.