Configure the BlackBerry UEM Client to support app-based certificates

This task is required only if you use your organization's app-based PKI solution with iOS devices and the PKI app is not a BlackBerry Dynamics app.
  1. In the management console, on the menu bar, click Apps.
  2. In the app list, click the BlackBerry UEM Client.
  3. In the App configuration section, click The Add icon > Create new.
  4. In the App name field, type a name for the app.
  5. In the UTI schemes field, specify the UTI schemes for your organization's app-based PKI solution. If you are using the Purebred app, use one of the following schemes:
    • Purebred Registration 2025 app: purebred2025.select.all-user, purebred2025.select.no-filter, purebred2025.zip.all-user, purebred2025.zip.no-filter
    • Pre-2025 Purebred app: purebred.select.all-user, purebred.select.no-filter, purebred.zip.all-user, purebred.zip.no-filter
    Note that the UTI schemes for the Purebred 2025 app take precedence over the UTI schemes for the pre-2025 Purebred app. It is recommended to not use both sets of Purebred UTI schemes, and to not have both the 2025 and pre-2025 Purebred apps on the same device, as it can cause issues when importing Purebred certificates into the UEM Client.
  6. Click Save.
  • Assign the UEM Client with the app configuration that you created to the users and devices you want to use the app-based PKI solution.
  • If you are using the pre-2025 Purebred app, you must turn off the following rule in the IT policy assigned to users: “Do not allow copying data from non BlackBerry Dynamics apps into BlackBerry Dynamics apps”.