So normally you'd deploy EJBCA internally. But what if you wanted to publicly use it for SCEP but not want to deploy the ManagementCA to user trust store?
That's when you'd put EJBCA behind a reverse proxy, but how?
did you know that you have to provide a full certificate trust chain for getting almost every web (or any SSL) client to use your website (or service) with TLS?
...but you can still visit some websites with your browser that don't do this?