Skip to main content

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_certservice_scep


Swarmauri Certservice SCEP

ScepCertService implements certificate enrollment using the Simple Certificate Enrollment Protocol (SCEP). It maps the generic ICertService flows onto SCEP operations so applications can request, receive, and validate X.509 certificates without dealing with protocol details.

Features

  • Generate RFC 2986-compliant PKCS#10 certificate signing requests with challenge passwords and subject alternative names.
  • Submit CSRs to SCEP responders via PKCSReq and retrieve issued certificates.
  • Download issuer CA certificates and validate issued leaf certificates for time window, issuer, and CA flags.
  • Parse returned certificates into structured dictionaries for downstream automation.

Prerequisites

  • Python 3.10 or newer.
  • An accessible SCEP server URL (for example, https://mdm.example.com/scep).
  • Private key material for each device or service enrolling via SCEP. Software keys can be embedded in the KeyRef.material field.
  • Optional: RA challenge password if your SCEP service requires one for enrollment.

Installation

# pip
pip install swarmauri_certservice_scep

# poetry
poetry add swarmauri_certservice_scep

# uv (pyproject-based projects)
uv add swarmauri_certservice_scep

Quickstart: Enroll a Device Certificate

import asyncio
from pathlib import Path

from cryptography.hazmat.primitives import serialization

from swarmauri_certservice_scep import ScepCertService
from swarmauri_core.certs.ICertService import SubjectSpec
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse


async def enroll() -> None:
    service = ScepCertService(
        "https://scep.example.test",
        challenge_password="enroll-secret",
    )

    key_bytes = Path("device.key.pem").read_bytes()
    key_ref = KeyRef(
        kid="device-key",
        version=1,
        type=KeyType.RSA,
        uses=(KeyUse.SIGN,),
        export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
        material=key_bytes,
    )

    subject: SubjectSpec = {
        "C": "US",
        "O": "Example Corp",
        "CN": "device-001.example.com",
    }

    csr_pem = await service.create_csr(
        key=key_ref,
        subject=subject,
        san={"dns": ["device-001.example.com", "device-001"]},
    )

    fullchain = await service.sign_cert(csr_pem, ca_key=key_ref)
    Path("device.pem").write_bytes(fullchain)
    print("Enrollment complete → device.pem")


if __name__ == "__main__":
    asyncio.run(enroll())

sign_cert returns the DER content provided by the SCEP server. Depending on your responder, the payload may be a single certificate or a PKCS#7 chain; decode accordingly before storing.

Verify Certificates from SCEP

import asyncio
from pathlib import Path

from swarmauri_certservice_scep import ScepCertService


async def verify() -> None:
    service = ScepCertService("https://scep.example.test")

    device_cert = Path("device.pem").read_bytes()

    result = await service.verify_cert(device_cert)
    if result["valid"]:
        print("Issuer:", result["issuer"])
        print("Valid until:", result["not_after"])
    else:
        print("Certificate failed validation:", result["reason"])

    details = await service.parse_cert(device_cert)
    print("Serial:", details["serial"])
    print("Subject alternative names:", details.get("san"))


if __name__ == "__main__":
    asyncio.run(verify())

verify_cert evaluates SCEP-issued certificates for validity windows and CA constraints, while parse_cert extracts SAN, EKU, and key usage metadata for logging or policy engines.

Operational Tips

  • Generate distinct key pairs per device or workload, and store them securely—KeyRef can reference HSM-backed keys instead of raw PEM material.
  • Capture challenge passwords and sensitive enrollment secrets from a secure vault or environment variables rather than hard-coding them in scripts.
  • If your SCEP responder returns PKCS#7 payloads, feed the response into cryptography.hazmat.primitives.serialization.pkcs7 to extract certificate chains before deployment.
  • Pair SCEP enrollment with Swarmauri revocation check services (swarmauri_certs_ocspverify, swarmauri_certs_crlverifyservice) to maintain lifecycle hygiene.

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_certservice_scep 0.8.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_certservice_scep 0.8.3
File Size Uploaded
swarmauri_certservice_scep-0.8.3.tar.gz 10.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_certservice_scep 0.8.3
File Interpreter ABI Platform
swarmauri_certservice_scep-0.8.3-py3-none-any.whl Python 3 none any Details

Total release size: 21.0 kB

Release files / swarmauri_certservice_scep-0.8.3.tar.gz

Download URL swarmauri_certservice_scep-0.8.3.tar.gz
Size 10.0 kB
Tags Source
SHA-256 checksum
How to use checksums
7bbca704952094ff5a14a5c133d4590f167d4d0474f88386b460fd1f20cc5282
BLAKE2b-256 checksum
How to use checksums
699abe8d82d7300dcebe0394b0e9e4abfc38a6aea3ef384bbfd6be9f6ec3153e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_certservice_scep-0.8.3-py3-none-any.whl

Download URL swarmauri_certservice_scep-0.8.3-py3-none-any.whl
Size 11.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7fb256c6a8842048ff4268fd5a080609b13b4fd602fc479d487c72f041847b51
BLAKE2b-256 checksum
How to use checksums
2da1ae3e973a901358416754b0a3816f481ad23b03659b639e8a955903654230
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page