<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SCEP Certificate missing required extensions in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422883#M10752</link>
    <description>&lt;P&gt;What in Meraki land are you using SCEP for?&lt;/P&gt;&lt;P&gt;If you open the Certificate Template in Microsoft CA server - what are listed as the required extensions?&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 00:05:08 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2023-07-07T00:05:08Z</dc:date>
    <item>
      <title>SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422882#M10751</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I tried renewing our SCEP cert with our Windows certification authority and it will not upload due to error "SCEP Certificate missing required extensions". We dont use OPENSSL for our CA so the instructions and help article do not help... What are the required extensions??&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 19:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422882#M10751</guid>
      <dc:creator>Boogis</dc:creator>
      <dc:date>2023-07-06T19:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422883#M10752</link>
      <description>&lt;P&gt;What in Meraki land are you using SCEP for?&lt;/P&gt;&lt;P&gt;If you open the Certificate Template in Microsoft CA server - what are listed as the required extensions?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 00:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422883#M10752</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2023-07-07T00:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422884#M10753</link>
      <description>&lt;P&gt;I would guess for Wi-Fi security and authentication, but I am not sure why we are using that. Since it would make the Meraki portal a subordinate CA, i believe it would use the subordinate CA template. That one I have set to only require a common name. Systems manager has a new requirement that an additional file is icreated when the cert is generated. I created a template that has these extra settings but still no luck with the cert.&lt;/P&gt;&lt;P&gt;Where `configuration_file.ext` contains the following extension value pairs:&lt;/P&gt;&lt;DIV class=""&gt;basicConstraints = critical,CA:true,pathlen:0&lt;BR /&gt;keyUsage = critical,keyCertSign,digitalSignature&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Jul 2023 21:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422884#M10753</guid>
      <dc:creator>Boogis</dc:creator>
      <dc:date>2023-07-10T21:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422885#M10754</link>
      <description>&lt;P&gt;I'm having the same issue trying to update my expired SCEP certificate. I've tried using the built-in SubCA template in ADCS as well as created new templates, but I cannot seem to get the Meraki Dashboard to accept anything signed by ADCS.&lt;BR /&gt;&lt;BR /&gt;Here are the basic constraints and key usage settings in my SubCA template.&lt;BR /&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-25 at 11.17.31 am.png" style="width: 322px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263659i9C49A7E834ECEE3A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-25 at 11.17.39 am.png" style="width: 289px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263663i86539C06DC9B171D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And the resulting signed certificate from the Meraki CSR:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-25 at 11.19.35 am.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263661i0F2742CC06EC3C04/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-25 at 11.19.54 am.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263662i9DF7A7C16CE254D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-25 at 11.20.10 am.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263664iBA974A00559419D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Has anyone been able to get this working with the newer requirements and ADCS?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 00:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422885#M10754</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-01-25T00:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422886#M10755</link>
      <description>&lt;P&gt;Okay, I was able to use the following workaround in my lab environment to update the SCEP certificate.&lt;/P&gt;&lt;P&gt;Using OpenSSL to sign the certificate is not ideal as that certificate would live outside of the control and knowledge of ADCS.&lt;/P&gt;&lt;P&gt;However, since this is just a lab environment, I was able to use the following option to extract the Root CA cert and key from my ADCS in p12 format.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.citrix.com/article/CTX224970/how-to-export-internal-root-ca-with-private-key-from-microsoft-certificate-authority-services-to-use-on-netscaler-swg" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.citrix.com/article/CTX224970/how-to-export-internal-root-ca-with-private-key-from-microsoft-certificate-authority-services-to-use-on-netscaler-swg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I was then able to use the openssl commands in this document to extract the certificate and key in PEM format and then use OpenSSL to sign the Meraki SCEP cert.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ssl.com/how-to/export-certificates-private-key-from-pkcs12-file-with-openssl/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.ssl.com/how-to/export-certificates-private-key-from-pkcs12-file-with-openssl/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I doubt this option would be acceptable for a customer Production environment, but it works for my lab setup.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422886#M10755</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-01-29T06:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422887#M10756</link>
      <description>&lt;P&gt;Well done.  Clever work around.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 19:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422887#M10756</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-01-29T19:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422888#M10757</link>
      <description>&lt;P&gt;Sorry to resurrect this old thread, but is there any solution to this?  I'm having a similar issue signing the CSR with any type of template and uploading to meraki.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 17:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422888#M10757</guid>
      <dc:creator>caug1</dc:creator>
      <dc:date>2025-03-12T17:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422889#M10758</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/70949"&gt;@Boogis&lt;/A&gt; , thank you for raising this question!&lt;/P&gt;&lt;P&gt;Were you able to resolve this issue? If so, we would love to hear more about it. If not, we recommend submitting a case on our Dashboard under ? &amp;gt; Get Help &amp;amp; Cases so we can further investigate the renewal process for SCEP certificate under your SM network.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 19:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422889#M10758</guid>
      <dc:creator>PriscillaX</dc:creator>
      <dc:date>2025-03-13T19:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422890#M10759</link>
      <description>&lt;P&gt;Did you try Grgibbs solution? We did not end up moving forward with it so I'm not sure if it works.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 20:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422890#M10759</guid>
      <dc:creator>Boogis</dc:creator>
      <dc:date>2025-03-13T20:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422891#M10760</link>
      <description>&lt;P&gt;No. We had given up or decided it was not worth the trouble.&lt;/P&gt;&lt;P&gt;If we revisit the issue, I will certainly do that. Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 20:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422891#M10760</guid>
      <dc:creator>Boogis</dc:creator>
      <dc:date>2025-03-13T20:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422892#M10761</link>
      <description>&lt;P&gt;I recently went through the process of signing the SCEP certificate for another separate lab environment and found Meraki still threw the same error when I signed it using the Intermediate CA template in ADCS.&lt;/P&gt;&lt;P&gt;I had to use the same workaround above with OpenSSL to get it to work.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Mar 2025 21:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422892#M10761</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-03-16T21:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: SCEP Certificate missing required extensions</title>
      <link>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422893#M10762</link>
      <description>&lt;P&gt;Since I just found this topic from the error message and managed to figure out the problem, I figured I would post the solution...&lt;/P&gt;&lt;P&gt;The issue with the AD subordinate cert is that it was missing pathlen:0, which is what prohibits this CA from issuing more subordinate certs. This is a cert policy construct that we can edit with a command on our Microsoft CA:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;from a cmd prompt with administrative rights on your CA server run the command&lt;/P&gt;&lt;P&gt;&amp;gt; certutil -setreg Policy\CAPathLength 1&lt;/P&gt;&lt;P&gt;After you issue that command go and resubmit your CA request and get your cert (rename the file extension to crt) the dashboard now will accept it.&lt;/P&gt;&lt;P&gt;more info on&lt;/P&gt;&lt;H1 id="toc-hId-1846904899"&gt;Constraints&lt;/H1&gt;&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/constraints-what-they-are-and-how-they8217re-used/1129048" target="_blank" rel="noopener nofollow noreferrer"&gt;https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/constraints-what-they-are-and-how-they8217re-used/1129048&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Apr 2025 13:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/scep-certificate-missing-required-extensions/m-p/5422893#M10762</guid>
      <dc:creator>esherwoo</dc:creator>
      <dc:date>2025-04-13T13:56:25Z</dc:date>
    </item>
  </channel>
</rss>

