SimpleSCEPGet started
Apache 2.0 · Open source

Private PKI, made simple.

Self-host SCEP, ACME, and EST certificate issuance for MDM fleets, servers, and private infrastructure, with keys protected by the cloud KMS you control.

SCEP · ACME · EST
Software or HSM keys per CA
MDM & server ready

One self-hosted control plane for private certificates

SimpleSCEP gives teams automated certificate enrollment, renewal, revocation, and lifecycle management while keeping the deployment and trust boundary under their control.

SCEP enrollment for MDM

  • Works with MDMs that support SCEP
  • Intune and Jamf Pro connectors built in
  • Dynamic challenges and automatic revocation
  • Standard SCEP endpoints you operate

Private ACME automation

  • Renew internal TLS with any ACME client
  • Authorised by credentials you issue
  • No public CA dependency
  • Built for private services

EST and enterprise PKI

  • EST enrollment and re-enrollment
  • Dedicated roots and issuing CAs
  • Multi-tier CA hierarchies
  • Policy controls per endpoint

IoT and device identity

  • A unique certificate per device
  • Mutual TLS for gateways and services
  • Fleet-scale enrollment
  • Durable identity that survives renewal

Built like the control plane it is

A private CA is only as trustworthy as the account and infrastructure that administer it. Security capabilities are part of the project, not paid upgrades.

We take security seriously

SimpleSCEP is built on a foundation of security best practices to ensure your infrastructure is protected.

Sensitive actions are confirmed

Revoking, rotating, and deleting ask you to prove it is still you, even mid-session.

Complete audit trail

Every action is recorded and exportable whenever an auditor asks for it.

Keys that cannot be exported

Choose software- or HSM-backed CA keys for each authority using Google Cloud KMS or Azure Key Vault.

Revocation you can rely on

CRL and OCSP responders answer independently of the dashboard, so revocation keeps working even when other things do not.

Expiry alerts before an outage

Certificates nearing expiry raise an email to your team, on a threshold you choose.

Open source, deploy it your way

SimpleSCEP is available under Apache License 2.0. Run it in your environment, inspect the complete implementation, and contribute through GitHub.

SimpleSCEP FAQ

What certificate enrollment protocols does SimpleSCEP support?

SCEP for MDM and device enrollment, ACME for private server certificates, and EST for enrollment and re-enrollment. ACME accounts authorise with External Account Binding rather than public domain validation.

Who is SimpleSCEP built for?

IT, security, platform, and infrastructure teams managing device fleets, internal servers, IoT devices, and private certificate authorities.

Which MDMs does it work with?

Any MDM that speaks SCEP. Microsoft Intune and Jamf Pro have connectors built in — Intune with an admin-consent flow and an automatic revocation sweep, Jamf Pro with dynamic challenges — and everything else enrolls against a standard SCEP endpoint with a shared secret or one-time challenge.

Where do I run SimpleSCEP?

You run SimpleSCEP in your own environment with PostgreSQL and either Google Cloud KMS or Azure Key Vault for production key protection. A disposable local mode is available for development.

Can I bring my own certificate authority?

Yes. You can create a new hierarchy or import an existing root or issuing CA so your current trust chain keeps working.

Can I use HSM-backed keys?

Yes. Each certificate authority can independently use software- or HSM-backed keys through Google Cloud KMS or Azure Key Vault.

What does a production deployment require?

A production deployment uses PostgreSQL, Resend, HTTPS, and either Google Cloud KMS or Azure Key Vault for non-exportable CA keys and encrypted application secrets.