trending

Are you are still using legacy SCEP protocol to manage your device identity certificates?

  • SCEP relies on shared challenge passwords that are easily intercepted from MDMs or disgruntled staff. Once leaked, any rogue device can request a trusted certificate, leaving you unable to distinguish a corporate laptop from a hacker s virtual machine.

  • SCEP allows private keys to be generated in software, meaning they can be exported, cloned, and moved to unauthorized hardware. A single stolen SCEP-issued certificate opens your entire enterprise security perimeter to persistent, untraceable access.

  • SCEP lacks any mechanism to verify the TPM or Secure Enclave, simply assuming the device is legitimate. In an era of sophisticated device spoofing, this lack of hardware attestation is a guaranteed recipe for a major breach.

ACME Device Attestation addresses all these problems by offering a password-less device identity-aware network access with hardware-rooted security. Security is no longer based on what you know (the passwords) but what you own (the company approved device/hardware).

21h ago

BastionXP - Issue TPM/SE hardware-attested X.509 certificates to devices

BastionXP is a cloud-native private PKI CA that performs ACME Device Attestation (hardware attestation + private key in TPM/SE/vTPM/HSM) before signing and issuing short-lived X.509 digital certificates to laptops, mobile devices, IoT, workloads using the ACME protocol. Secures access to your enterprise Wi-Fi, VPN, SaaS apps, MCP gateway/clients in your enterprise network using EAP-TLS and mTLS client authentication. Replaces the legacy SCEP protocol platforms that uses shared credentials.