Cisco ISE’s BYOD onboarding workflow uses Simple Certificate Enrollment Protocol to request and obtain a unique endpoint certificate from the configured certificate authority, including the ISE internal CA when that service is selected. SCEP is specifically designed for certificate-enrollment and related PKI operations. Therefore, B is correct. CMP is another certificate-management protocol, but it is not the protocol used by the ISE BYOD provisioning workflow described here. SFTP securely transfers files and cannot perform certificate enrollment. OCSP determines whether an already-issued certificate has been revoked; it does not request or issue certificates. The resulting per-device certificate establishes a unique endpoint identity and supports certificate-based network authentication, commonly through EAP-TLS, after the BYOD onboarding process is completed. Cisco SCEP overview
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit