• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
We are proud to announce new Poly Studio Series video bars and remote room control with Poly Connect. Read more about the solutions!
HP Recommended

SCEP support for Studio X or G7500

 

Browse to Studio X or G7500 and navigate to Security > Certificates > SCEP > View and enter the SCEP details.

 

The below example is using a Windows 2019 Server.

 

The SCEP Challenge Password is the enrollment challenge password when using a Windows Server

SteffenBaierUK_0-1714752511392.png

 

The Common Name (CN) is the Network > Lan Network > Lan Options > Host Name 

SteffenBaierUK_0-1717795986434.png

 

The Studio X or G7500/G62 Web UI once the Certificate is succesfully installed:

SteffenBaierUK_1-1714752576272.png

 

With PolyOS 4.2 the TC device (running TCOS 6.0.0 or later) added SCEP support so the TC device can download the Root and the Device certificate.

SteffenBaierUK_2-1714752595721.png

 

NOTE: At present, the TC device does not support the dynamic challenge passwords as it gets a copy of the SCEP information from a paired Studio X or G7500. When using dynamic single-use passwords only the paired Studio X or G7500 will be able to gather device certificates. 

When applying the Device Certificate to both the Studio / G7500 / G62 or the TC device ensure it has Client Authentication or when using TLS the server cannot Authenticate the Certificate:

SteffenBaierUK_0-1717500794131.png

 

SteffenBaierUK_1-1717500844746.png

 

False:

SteffenBaierUK_3-1717500943910.png

 

To allow a Windows SCEP/NDES Server to use a static SCEP Challenge Password follow >this<

 

 

 

•Location: HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\MSCEP\UseSinglePassword
•Name: UseSinglePassword
•Type: REG_DWORD
•Value: 1

 

 

 

 

SteffenBaierUK_0-1714744336855.png


As the password is now static it needs to be stored via the registry, the user account used for the NDES service account should therefore be granted Full control write permission via Allow to the MSCEP registry key.

SteffenBaierUK_0-1714751759320.png

 SteffenBaierUK_1-1714751769041.png

 

In addition the IIS Application Pool for SCEP, if the NDES service account is a domain account, the "Load User Profile" option must still be enabled in the advanced configuration of the IIS application pool.

SteffenBaierUK_2-1714751901164.png

or via Power Shell:

 

 

 

Import-Module -Name WebAdministration
Set-ItemProperty IIS:\AppPools\SCEP -name processModel -value @{LoadUserProfile="true"} 

 

 

 

 

Don't forget to reboot the SCEP server or simply restart IIS

SteffenBaierUK_3-1714751958401.png

Source

------------------------------------------------
Notice: I am an HP Poly employee but all replies within the community are done as a volunteer outside of my day role. This community forum is not an official HP Poly support resource, thus responses from HP Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge.
If you need immediate and/or official assistance for former Poly\Plantronics\Polycom please open a service ticket through your support channels
For HP products please check HP Support.

Please also ensure you always check the General VoIP , Video Endpoint , UC Platform (Microsoft) , PSTN
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.