Skip Navigation

Configuring
Kerberos
for
BlackBerry Dynamics
apps

BlackBerry Dynamics
apps support both
Kerberos
Constrained Delegation and
Kerberos
PKINIT.
Kerberos
Constrained Delegation (KCD) and
Kerberos
PKINIT are distinct implementations of
Kerberos
. You can support one or the other for
BlackBerry Dynamics
apps, but not both.
Kerberos
Constrained Delegation uses a previously established trust relationship between
BlackBerry UEM
and the
Windows
Key Distribution Center (KDC).
BlackBerry UEM
communicates with KDC on behalf of the app.
Kerberos
Constrained Delegation takes precedence over
Kerberos
PKINIT, even if the user has a valid certificate. For general information on how
Kerberos
Constrained Delegation works with
BlackBerry Dynamics
apps, see
Kerberos
Constrained Delegation with
Good Control
.
Kerberos
PKINIT authentication establishes trust directly between the
BlackBerry Dynamics
app and the
Windows
KDC. User authentication is based on certificates issued by
Microsoft Active Directory
Certificate Services. To use PKINIT,
Kerberos
Constrained Delegation must not be enabled in the app settings in
BlackBerry UEM
.