Skip Navigation

Support for certificates

Type
Description
PKI certificates
BlackBerry Dynamics
 supports many popular uses of client-side Public Key Infrastructure (PKI) certificates to secure apps and communications:
  • General requirements for working with PKI certs
  • Description of client certificate sharing among 
    BlackBerry Dynamics
     apps on a device
  • Kerberos
     PKINIT: Client certificates in the 
    Kerberos
     authentication model. This is not 
    Kerberos
     Constrained Delegation (KCD).
For more information, see Details of support for client certificates.
SCEP
BlackBerry UEM
 version 12.10 and later support certificate enrollment using SCEP with 
Entrust
 and 
Microsoft
 NDES for 
BlackBerry Dynamics
 apps. Administrators can configure and assign a SCEP profile for 
BlackBerry Dynamics
 apps in the 
UEM
 management console.
For more information, see “SCEP profile settings” in the UEM Administration Guide
Device-based certificate retrieval
BlackBerry UEM
 version 12.10 and later enables the 
BlackBerry Dynamics Runtime
 to enroll certificates from a device's 
Android
 key chain instead of getting them from the server. These certificates can be used to sign and decrypt data for SMIME emails and to perform client certificate-based authentication on TLS connections, using private keys that are saved in the 
Android
 key chain. Administrators can configure and assign a user credential profile to control this behavior.
For more information, see “Using user credential profiles to send certificates to devices” in the UEM Administration Guide