Using this simple yet effective technique, the OpenTrust implementation of the SCEP protocol cannot be used to impersonate another user when enrolling for an X.509 certificate.