yeah I followed that to the letter. I extracted the private key from my root CA (I'm using Microsoft CA) in order to sign this with openssl.

Then I go to create a SCEP cert config and that's where things get stuck

I feel there's something in between that I'm missing but not sure