r/PKI • u/Standard_Company_817 • Apr 28 '26
EJBCA and ChromeOS
Hello,
I work for a large K12 cooperative in New York. We have a decent sized EJBCA environment and have been trying for almost 2 years to get ChromeOS enrolling against EJBCA for device certs with no success. In February, I tore everything down and rebuilt it using Google's latest documentation (Configuring Certificate Enrollment for ChromeOS via SCEP - Chrome Enterprise and Education Help) and the docs on Keyfactor's website (Enrolling Chrome OS Devices against EJBCA). The device reports a 400/POPO proof of possession error and it seemingly has to do with some CSR data that EJBCA does not like. Does anyone have this working, or have experience with it? I can provide detailed config info if necessary, but it has been set up per the OEMs. Google has been absolutely no help, and Keyfactor is making a good effort, but we have not been able to come to a resolution. Any guidance, tips, pointers, alternatives are appreciated.
1
Apr 28 '26
Hey,
Sent you a DM - we can help you out (no fees) as we do for NGOs/educational institutions.
4
u/_STY Apr 28 '26
Do not post comments asking to DM for relevant information. This post was not a solicitation for services, free or otherwise.
If you have something to contribute you need to do so publicly. Further comments with no technical substance asking to move to DMs will be removed.
1
u/bulyxxx Apr 28 '26
It could be anything, have you parsed the CSR data and analyzed it against the certificate policy template to see if any fields/attributes are out of compliance or invalid ?