Related user story
Task
Allow $FLEET_VAR_NDES_SCEP_CHALLENGE in scripts: saved scripts, ad-hoc scripts, software install, post-install and uninstall scripts (including script-only packages), setup experience scripts, and Fleet-maintained app scripts. Shell, Python, and PowerShell.
When a host fetches a script that references the variable, Fleet requests a one-time challenge from the configured Okta / Microsoft NDES certificate authority and makes the value available to the script the same way the existing host and IdP variables are, so the script can place it in the CSR's challengePassword attribute before calling the "Request certificate" API. One challenge is requested per script fetch, however many times the variable appears.
If no NDES CA is configured, or the CA cannot supply a challenge (unreachable, rejected credentials, NDES password cache full), the script does not run and the failure is recorded with a message that names the cause, the same way an unresolvable IdP variable is handled today. The challenge value is never written to server logs.
Upload validation accepts the variable wherever the other script variables are accepted. Fleet Premium only, as for all script variables. No UI, fleetctl, GitOps, fleetd, REST API, or schema changes. Documentation was merged separately (#54252).
This replaces the "Request certificate challenge" endpoint (#53780), which was closed.
Condition of satisfaction
- A script containing
$FLEET_VAR_NDES_SCEP_CHALLENGE can be saved, run ad-hoc, and uploaded as a script-only package or install/post-install/uninstall script on Fleet Premium; on Fleet Free the upload is rejected with the existing variables license message.
- When such a script runs on a Linux, macOS, or Windows host with an NDES CA configured, the variable resolves to a fresh challenge and a CSR carrying it is issued by the CA through the "Request certificate" API.
- Two hosts fetching the same script receive different challenges; a script that references the variable twice consumes one challenge.
- With no NDES CA configured, the script is not run and the recorded output says NDES is not configured.
- When the NDES admin URL is unreachable, returns an error, rejects the credentials, or reports a full password cache, the script is not run and the recorded output names that cause; the host's script queue keeps processing.
- Scripts that reference only other variables, or none, behave exactly as before.
- The challenge value appears in no server log line at any level.
- Unit tests cover resolution, the single-fetch guarantee, each failure cause, and the license gate, using the in-repo NDES admin test fixture.
Related user story
Task
Allow
$FLEET_VAR_NDES_SCEP_CHALLENGEin scripts: saved scripts, ad-hoc scripts, software install, post-install and uninstall scripts (including script-only packages), setup experience scripts, and Fleet-maintained app scripts. Shell, Python, and PowerShell.When a host fetches a script that references the variable, Fleet requests a one-time challenge from the configured Okta / Microsoft NDES certificate authority and makes the value available to the script the same way the existing host and IdP variables are, so the script can place it in the CSR's
challengePasswordattribute before calling the "Request certificate" API. One challenge is requested per script fetch, however many times the variable appears.If no NDES CA is configured, or the CA cannot supply a challenge (unreachable, rejected credentials, NDES password cache full), the script does not run and the failure is recorded with a message that names the cause, the same way an unresolvable IdP variable is handled today. The challenge value is never written to server logs.
Upload validation accepts the variable wherever the other script variables are accepted. Fleet Premium only, as for all script variables. No UI, fleetctl, GitOps, fleetd, REST API, or schema changes. Documentation was merged separately (#54252).
This replaces the "Request certificate challenge" endpoint (#53780), which was closed.
Condition of satisfaction
$FLEET_VAR_NDES_SCEP_CHALLENGEcan be saved, run ad-hoc, and uploaded as a script-only package or install/post-install/uninstall script on Fleet Premium; on Fleet Free the upload is rejected with the existing variables license message.