Skip Navigation

Sending client certificates to devices and apps using user credential profiles

User credential profiles allow devices to use client certificates obtained by the following methods:
  • Manually uploading certificates to the 
    BlackBerry UEM
     management console or, in an on-premises environment, to 
    BlackBerry UEM Self-Service
  • An established connection between 
    BlackBerry UEM
     and your organization’s 
    Entrust
     CA or 
    OpenTrust
     CA
  • For 
    BlackBerry Dynamics
     apps on 
    Android
     devices, certificates stored in the device native keystore
  • For 
    BlackBerry Dynamics
     apps, through an established 
    BlackBerry Dynamics
     PKI connector connection
  • For 
    BlackBerry Dynamics
     apps, using an app-based PKI solution such as 
    Purebred
If users manually upload certificates in 
UEM Self-Service
, you can see the certificate on the user page in the management console. You can also delete or replace the certificate. This feature is not supported in 
BlackBerry UEM Cloud
User credential profiles are supported on 
iOS
 and 
Android
 devices, and on devices running 
BlackBerry 10 OS
 version 10.3.1 and later. App-based PKI solutions are supported for 
BlackBerry Dynamics
 apps on 
iOS
 and 
Android
 devices. Manually uploading certificates is supported for 
iOS
Android Enterprise
Samsung Knox Workspace
, and 
BlackBerry 10
 devices.
For more information about connecting 
BlackBerry UEM
 to your organization's PKI software, see Integrating BlackBerry UEM with your organization's PKI software.
Alternatively, you can use SCEP profiles to enroll client certificates to devices. You can also upload certificates directly to a user account. The type of profile you choose depends on how your organization uses the PKI software, the types of devices your organization supports, and how you want to manage certificates.