Reference
Troubleshooting
Common enrollment and certificate authority errors.
Check recent enrollments
The endpoint's Recent enrollments log includes successful requests and authenticated refusals with their reasons.

Common errors
| What you see | What it actually is |
|---|---|
0x800700CE, "Failed to Initialize SCEP enrollment" on Windows |
Remove /pkiclient.exe from the configured URL. Windows appends it automatically |
| A TLS or certificate verification error from an ACME or EST client | The client does not trust the root. Distribute it before enrollment |
404 from an endpoint that exists |
The endpoint is disabled or deleted. Check its state in the protocol console |
| An ACME client renews nothing and reports nothing | Check order history. The endpoint may have been deleted or its credential revoked |
SCEP
| Symptom | Cause | Fix |
|---|---|---|
badRequest |
Malformed PKCS#7, or a digest the endpoint does not accept | Configure SHA-256. Enable the legacy switch only if the client genuinely cannot |
badIdentity |
The challenge expired, was already used, or belongs to another endpoint | Mint a fresh challenge. Check the device points at the endpoint you think it does |
badAlg |
Key type or size not permitted | Align the MDM profile's key settings |
badCertId |
A renewal signed by a certificate that is revoked, expired, or was not issued by this endpoint | Enroll fresh with a challenge |
| Refused: usage not permitted | The CSR asked for an extended key usage the endpoint does not permit | Widen the endpoint's permitted list, or narrow the MDM profile. It is never silently narrowed |
| Refused: subject does not match | The subject pattern rejected the CSR | The pattern matches the rendered subject — anchor on CN, and match email through the SAN pattern |
| Renewal refused, too early | The device asked outside the renewal window | Widen the window to at least what the fleet's renewal timer uses |
| Certificate issued but missing a usage | The CSR asked for nothing, so it received client authentication only | Have the profile request the usage explicitly |
ACME
| Symptom | Cause |
|---|---|
badNonce in the logs |
Normal. Clients fetch a fresh nonce and retry automatically |
| Order refused, naming an identifier | The endpoint's SAN pattern or the credential's pin does not allow that name. Checked at order time, before the client generates a key |
| Wildcard refused | Wildcards are not supported. Name each host |
| Finalize refused | The CSR does not exactly match the authorized identifiers, or carries an email, URI, or otherName SAN. Usually means the client was reconfigured between ordering and finalizing |
| Account cannot order any more | Its credential was revoked, which deactivates every account that credential registered |
| Client skips the challenge and goes straight to finalize | Expected. Authorizations are created valid — see ACME |
EST
| Symptom | Cause |
|---|---|
403, no authentication prompt |
The request arrived over plaintext. Fix the TLS termination in front of the endpoint. If a password was sent, revoke and re-mint it — it has already crossed the wire |
401 |
Wrong username, wrong password, or a revoked credential |
/simplereenroll refused |
Either the subject has never held a certificate from this endpoint, or the request is outside the renewal window |
| Renewals stopped for a whole fleet at once | The credential expired. An EST credential bounds enrollment and renewal — unlike ACME, where a registered client keeps working |
404 from /serverkeygen |
Not implemented. Clients fall back to /simpleenroll |
| A client defaults to RSA-2048 when you wanted EC | It ignored /csrattrs, or the CA has nothing to advertise. Configure the key type on the client |
Certificate authorities
| Symptom | Cause |
|---|---|
| "Disable or rebind endpoints before …" | An enabled endpoint is bound to that CA. The message names which protocol |
| Cannot delete a CA | It has live subordinates. Delete those first |
| CRL publication failed | Check the reason on the CA row |
| Import stuck in "preparing" | SimpleSCEP is provisioning the import target. Failures include a reason and can be canceled and restarted |
Still stuck
Search or open a GitHub Issue. Include the version, endpoint type, approximate time, and redacted client error. Do not include passwords, credentials, private keys, or sensitive certificate material. Report suspected vulnerabilities privately through the project's security policy.