Check recent enrollments

The endpoint's Recent enrollments log includes successful requests and authenticated refusals with their reasons.

An endpoint's Recent enrollments log, showing issuance and refusals with their reasons

Common errors

What you see What it actually is
0x800700CE, "Failed to Initialize SCEP enrollment" on Windows Remove /pkiclient.exe from the configured URL. Windows appends it automatically
A TLS or certificate verification error from an ACME or EST client The client does not trust the root. Distribute it before enrollment
404 from an endpoint that exists The endpoint is disabled or deleted. Check its state in the protocol console
An ACME client renews nothing and reports nothing Check order history. The endpoint may have been deleted or its credential revoked

SCEP

Symptom Cause Fix
badRequest Malformed PKCS#7, or a digest the endpoint does not accept Configure SHA-256. Enable the legacy switch only if the client genuinely cannot
badIdentity The challenge expired, was already used, or belongs to another endpoint Mint a fresh challenge. Check the device points at the endpoint you think it does
badAlg Key type or size not permitted Align the MDM profile's key settings
badCertId A renewal signed by a certificate that is revoked, expired, or was not issued by this endpoint Enroll fresh with a challenge
Refused: usage not permitted The CSR asked for an extended key usage the endpoint does not permit Widen the endpoint's permitted list, or narrow the MDM profile. It is never silently narrowed
Refused: subject does not match The subject pattern rejected the CSR The pattern matches the rendered subject — anchor on CN, and match email through the SAN pattern
Renewal refused, too early The device asked outside the renewal window Widen the window to at least what the fleet's renewal timer uses
Certificate issued but missing a usage The CSR asked for nothing, so it received client authentication only Have the profile request the usage explicitly

ACME

Symptom Cause
badNonce in the logs Normal. Clients fetch a fresh nonce and retry automatically
Order refused, naming an identifier The endpoint's SAN pattern or the credential's pin does not allow that name. Checked at order time, before the client generates a key
Wildcard refused Wildcards are not supported. Name each host
Finalize refused The CSR does not exactly match the authorized identifiers, or carries an email, URI, or otherName SAN. Usually means the client was reconfigured between ordering and finalizing
Account cannot order any more Its credential was revoked, which deactivates every account that credential registered
Client skips the challenge and goes straight to finalize Expected. Authorizations are created valid — see ACME

EST

Symptom Cause
403, no authentication prompt The request arrived over plaintext. Fix the TLS termination in front of the endpoint. If a password was sent, revoke and re-mint it — it has already crossed the wire
401 Wrong username, wrong password, or a revoked credential
/simplereenroll refused Either the subject has never held a certificate from this endpoint, or the request is outside the renewal window
Renewals stopped for a whole fleet at once The credential expired. An EST credential bounds enrollment and renewal — unlike ACME, where a registered client keeps working
404 from /serverkeygen Not implemented. Clients fall back to /simpleenroll
A client defaults to RSA-2048 when you wanted EC It ignored /csrattrs, or the CA has nothing to advertise. Configure the key type on the client

Certificate authorities

Symptom Cause
"Disable or rebind endpoints before …" An enabled endpoint is bound to that CA. The message names which protocol
Cannot delete a CA It has live subordinates. Delete those first
CRL publication failed Check the reason on the CA row
Import stuck in "preparing" SimpleSCEP is provisioning the import target. Failures include a reason and can be canceled and restarted

Still stuck

Search or open a GitHub Issue. Include the version, endpoint type, approximate time, and redacted client error. Do not include passwords, credentials, private keys, or sensitive certificate material. Report suspected vulnerabilities privately through the project's security policy.