Apple prompted users to explicitly test SCEP workflows after the Ventura upgrade. The Apple MacOS 13 Beta 1 Release Notes should cover the changes, but we didn't find any more details.
Did Apple release any more information on what was changed?
We are currently unable to complete the SCEP workflow on Ventura 13.0 22A380. Up to macOS Monterey the workflow works without any problems.
The workflow fails while parsing the PKCSReq response (Diagram #5) with the following error:
CertificateService [502:Cert_PI:SCEP:<0xf94c>] Calling SecSCEPVerifyReply()...
CertificateService SecCMSMessageSecurityShim is disabled (via feature flags)
CertificateService [502:Cert_PI:SCEP:<0xf94c>] SecSCEPVerifyReply() returned 0 certs Error: (null)
CertificateService [502:Cert_PI:SCEP:<0xf94c>] SCEP response verification failure details (PKCSReq):
CertificateService [502:Cert_PI:SCEP:<0xf94c>] ParseErrorCode : -25293
CertificateService [502:Cert_PI:SCEP:<0xf94c>] ResponseLength : 4961
CertificateService [502:Cert_PI:SCEP:<0xf94c>] ParseErrorText : Failed to verify signed data
CertificateService [502:Cert_PI:SCEP:<0xf94c>] Attrs attributes: (null)
CertificateService [ERROR] [502:Cert_PI:SCEP:<0xf94c>] SCEP response failed to verify ==> (null)
CertificateService [502:Cert_PI:<0xf94c>] <OUTERROR> Failed to verify get certificate response <MDM-SCEP:15002>
CertificateService [ERROR] [502:Cert_PI:SCEP:<0xf94c>] [CE] Certificate request failed ==> Failed to verify get certificate response <MDM-SCEP:15002>