# Overview

SimpleSCEP is an open-source, self-hosted private PKI. Create certificate authorities, set issuance policy, and enable enrollment protocols in infrastructure you control.

- **SCEP** — MDM-managed devices, including Intune, Jamf Pro, Workspace ONE, Ivanti, Kandji, and Mosyle.
- **ACME** — automated clients such as cert-manager, Caddy, Traefik, certbot, lego, and acme.sh.
- **EST** — network infrastructure such as strongSwan, Cisco IOS, appliances, and IoT fleets.

Production CA private keys are generated in Google Cloud KMS or Azure Key Vault and are non-exportable. Each CA independently selects software- or HSM-backed protection.

## How it fits together

```text
Organization
└── Root CA                            (signs nothing but issuing CAs)
    ├── Issuing CA "Devices"
    │   ├── SCEP endpoint  → Intune-managed Windows laptops
    │   └── SCEP endpoint  → Jamf-managed Macs
    └── Issuing CA "Infrastructure"
        ├── ACME endpoint  → Kubernetes ingress, internal TLS
        └── EST endpoint   → branch VPN gateways
```

- An organization holds one root CA and one or more issuing CAs beneath it.
- Each issuing CA carries an **issuance profile** — the extended key usages it will sign.
- Each **endpoint** binds to one issuing CA and carries its own policy: validity, renewal window, permitted subjects, names, and usages.

Endpoints validate requests against their policy and send accepted requests to the issuing CA. Subjects and SANs are copied from the CSR.

## Choose a protocol

| Protocol                | Use for                            | Client authenticates with                                 | Renewal                                       |
| ----------------------- | ---------------------------------- | --------------------------------------------------------- | --------------------------------------------- |
| [SCEP](/protocols/scep) | Devices under an MDM               | Challenge password                                        | Signed `RenewalReq` inside the renewal window |
| [ACME](/protocols/acme) | Servers, ingress, service meshes   | External Account Binding credential, once at registration | A new order, on the client's own timer        |
| [EST](/protocols/est)   | Routers, gateways, appliances, IoT | HTTP Basic username and password                          | `/simplereenroll`                             |

Protocols can use separate issuing CAs and policies.

## Next steps

- [Quickstart](/quickstart) — from an empty organization to a certificate on a device.
- [Core concepts](/concepts) — authorities, endpoints, issuance policy, and identities.
- [Certificate authorities](/platform/certificate-authorities) — creating, rotating, and retiring authorities.
- [Revocation, CRL and OCSP](/platform/revocation) — withdrawing a certificate and telling relying parties.
- [Troubleshooting](/reference/troubleshooting) — what the common failures mean.
