# Troubleshooting

## Check recent enrollments

The endpoint's **Recent enrollments** log includes successful requests and authenticated refusals with their reasons.

![An endpoint's Recent enrollments log, showing issuance and refusals with their reasons](/assets/docs/scep-enrollments-troubleshoot.png)

## Common errors

| What you see                                                       | What it actually is                                                                                    |
| ------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ |
| `0x800700CE`, "Failed to Initialize SCEP enrollment" on Windows    | Remove `/pkiclient.exe` from the configured URL. Windows appends it automatically                      |
| A TLS or certificate verification error from an ACME or EST client | The client does not trust the root. Distribute it before enrollment                                    |
| `404` from an endpoint that exists                                 | The endpoint is disabled or deleted. Check its state in the protocol console                           |
| An ACME client renews nothing and reports nothing                  | Check order history. The endpoint may have been deleted or its credential revoked                      |

## SCEP

| Symptom                                | Cause                                                                                          | Fix                                                                                                |
| -------------------------------------- | ---------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- |
| `badRequest`                           | Malformed PKCS#7, or a digest the endpoint does not accept                                     | Configure SHA-256. Enable the legacy switch only if the client genuinely cannot                    |
| `badIdentity`                          | The challenge expired, was already used, or belongs to another endpoint                        | Mint a fresh challenge. Check the device points at the endpoint you think it does                  |
| `badAlg`                               | Key type or size not permitted                                                                 | Align the MDM profile's key settings                                                               |
| `badCertId`                            | A renewal signed by a certificate that is revoked, expired, or was not issued by this endpoint | Enroll fresh with a challenge                                                                      |
| Refused: usage not permitted           | The CSR asked for an extended key usage the endpoint does not permit                           | Widen the endpoint's permitted list, or narrow the MDM profile. It is never silently narrowed      |
| Refused: subject does not match        | The subject pattern rejected the CSR                                                           | The pattern matches the rendered subject — anchor on `CN`, and match email through the SAN pattern |
| Renewal refused, too early             | The device asked outside the renewal window                                                    | Widen the window to at least what the fleet's renewal timer uses                                   |
| Certificate issued but missing a usage | The CSR asked for nothing, so it received client authentication only                           | Have the profile request the usage explicitly                                                      |

## ACME

| Symptom                                                  | Cause                                                                                                                                                                              |
| -------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `badNonce` in the logs                                   | Normal. Clients fetch a fresh nonce and retry automatically                                                                                                                        |
| Order refused, naming an identifier                      | The endpoint's SAN pattern or the credential's pin does not allow that name. Checked at order time, before the client generates a key                                              |
| Wildcard refused                                         | Wildcards are not supported. Name each host                                                                                                                                        |
| Finalize refused                                         | The CSR does not exactly match the authorized identifiers, or carries an email, URI, or `otherName` SAN. Usually means the client was reconfigured between ordering and finalizing |
| Account cannot order any more                            | Its credential was revoked, which deactivates every account that credential registered                                                                                             |
| Client skips the challenge and goes straight to finalize | Expected. Authorizations are created valid — see [ACME](/protocols/acme)                                                                                                           |

## EST

| Symptom                                          | Cause                                                                                                                                                                 |
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `403`, no authentication prompt                  | The request arrived over plaintext. Fix the TLS termination in front of the endpoint. If a password was sent, revoke and re-mint it — it has already crossed the wire |
| `401`                                            | Wrong username, wrong password, or a revoked credential                                                                                                               |
| `/simplereenroll` refused                        | Either the subject has never held a certificate from this endpoint, or the request is outside the renewal window                                                      |
| Renewals stopped for a whole fleet at once       | The credential expired. An EST credential bounds enrollment _and_ renewal — unlike ACME, where a registered client keeps working                                      |
| `404` from `/serverkeygen`                       | Not implemented. Clients fall back to `/simpleenroll`                                                                                                                 |
| A client defaults to RSA-2048 when you wanted EC | It ignored `/csrattrs`, or the CA has nothing to advertise. Configure the key type on the client                                                                      |

## Certificate authorities

| Symptom                                | Cause                                                                                                     |
| -------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| "Disable or rebind endpoints before …" | An enabled endpoint is bound to that CA. The message names which protocol                                 |
| Cannot delete a CA                     | It has live subordinates. Delete those first                                                              |
| CRL publication failed                 | Check the reason on the CA row                                                                            |
| Import stuck in "preparing"            | SimpleSCEP is provisioning the import target. Failures include a reason and can be canceled and restarted |

## Still stuck

Search or open a [GitHub Issue](https://github.com/jacksongrow0/SimpleSCEP/issues). Include the version, endpoint type, approximate time, and redacted client error. Do not include passwords, credentials, private keys, or sensitive certificate material. Report suspected vulnerabilities privately through the project's [security policy](https://github.com/jacksongrow0/SimpleSCEP/security/policy).
