如何将变量与证书中的变量搭配使用 (ChromeOS)

问题

如何使用变量在 ChromeOS 设备上自定义证书?

环境

  • SCEP 证书。
  • ChromeOS 设备。

解决方案

您可以对 SAN 使用变量,但只能对支持的变量使用变量。下面列出了一些受支持的功能:
${DEVICE_DIRECTORY_ID}—Device’s directory ID
${USER_EMAIL}—Signed-in user’s email address
${USER_EMAIL_DOMAIN}—Signed-in user’s domain name
${DEVICE_SERIAL_NUMBER}—Device's serial number
${DEVICE_ASSET_ID}—Asset ID assigned to device by administrator
${DEVICE_ANNOTATED_LOCATION}—Location assigned to device by administrator
${USER_EMAIL_NAME}—First part (part before @) of signed-in user’s email address