Create a single sign-on profile
Single sign-on profiles are supported for
BlackBerry 10
and iOS
devices. To set up single sign-on authentication for BlackBerry
Dynamics
apps, see Configuring Kerberos for BlackBerry Dynamics apps. - If you want to configureKerberosauthentication forBlackBerry 10devices, locate your organization’sKerberosconfiguration file (krb5.conf).
- If you want to use certificate-based authentication foriOSdevices, create the necessary shared certificate profile or SCEP profile.
- On the menu bar, clickPolicies and Profiles.
- ClickNetworks and connections > Single sign-on.
- Click
.
- Type a name and description for the profile.
- Perform any of the following tasks:TaskStepsConfigureKerberosauthentication foriOSdevices
- Click theiOStab.
- UnderKerberos, click
.
- In theNamefield, type a name for the configuration.
- In thePrincipal namefield, type the name of theKerberosPrincipal, using the format<primary>/<instance>@<realm>(for example,user/admin@blackberry.example.com).
- In theRealmfield, type theKerberosrealm in uppercase letters (for example,EXAMPLE.COM).
- In theURL prefixesfield, type the URL prefix for the sites that you want devices to authenticate with. The prefix must begin with http:// or https://, and can include wildcard values (*) (for example,https://www.blackberry.example.com/*).
- To specify more URL prefixes, click
to add more fields.
- If you want to limit the configuration to specific apps, click
beside
App identifiers. Type the app bundle ID. You can use a wildcard value (*) to match the ID to multiple apps. (for example,com.company.*). - To specify more app identifiers, click
to add more fields.
- If you wantiOSdevices to use certificate-based authentication, in theCredentialsdrop-down list, clickCertificate,SCEP, orUser credential. In the certificate drop-down list, click the certificate profile that you want to use.
- ClickAdd.
- If necessary, repeat steps 2 to 11 to add anotherKerberosconfiguration.
ConfigureKerberosauthentication forBlackBerry 10devices- Click theBlackBerrytab.
- ClickBrowse. Navigate to and select your organization’sKerberosconfiguration file (krb5.conf).
Configure NTLM authentication or trusted domains for SCEP certificates forBlackBerry 10devices- Click theBlackBerrytab.
- UnderTrusted domains, click
.
- In theNamefield, type a name for the configuration.
- In theDomainfield, type a trusted subdomain or individual host where the domain credentials can be used to authenticate automatically. Type the server name as an FQDN, hostname, alias, or IP address. DNS names can contain wildcards (*).
- To specify more subdomains, click
to add more fields.
- ClickAdd.
- If necessary, repeat steps 2 to 6 to add another trusted domain.
- ClickAdd.
If necessary, rank profiles.