Certificate enrollment via SCEP

An increasing number of certificate-based VPN connections are being used to provide secure communications via public networks. The high levels of security provided by certificates comes at the price of significantly higher levels of effort in the administration and distribution of certificates. Most of this effort arises at branch offices or home offices within a geographically dispersed network structure.

A LANCOM VPN Router router requires the following components to establish a certificate-based VPN connection from a remote site to network at headquarters:

Note: The current version of LCOS supports only a public key infrastructure (PKI) with a root CA.

In the case of a conventionally structured VPN with certificates, the keys and certificates have to be loaded into each device manually and exchanged before they expire. The Simple Certificate Enrollment Protocol (SCEP) enables a secure and automatic distribution of certificates via a suitable server, so reducing the effort of roll-out and maintaining certificate-based network structures. There is no need for the key pair for the device to be generated by an external application and subsequently transferred to the device. Instead, the key pair is generated directly by the LANCOM VPN Router itself; the private portion of the key never has to leave the device, which results in a significant gain in security. A LANCOM VPN Router can automatically retrieve the CA root certificate and its own certificate from a central location.