Create a user credential profile to connect to your organization's PKI software
User credential profiles that connect to your organization's PKI software can enroll certificates for iOS and Android devices. If the connection is to Entrust PKI software, the user credential profile can also enroll certificates for BlackBerry Dynamics apps.
BlackBerry UEM doesn't support key history for certificates issued to BlackBerry Dynamics apps.
- Configure a connection to your organization's Entrust or OpenTrust software.
- Contact your organization’s Entrust or OpenTrust administrator to confirm which PKI profile you should select.
- Ask the Entrust or OpenTrust administrator for the profile values that you must provide.
- If your organization’s OpenTrust system is configured to return Escrowed Keys only, the OpenTrust administrator must verify that certificates are present for each user in the OpenTrust system. Assigning a user credential profile to users in UEM does not automatically create certificates for users in OpenTrust. In this scenario, a user credential profile can only distribute certificates to users who have an existing certificate in the OpenTrust system.
- If devices use client certificates to authenticate with a Wi-Fi network, VPN, or mail server, associate the user credential profile with a Wi-Fi, VPN, or email profile.
- Assign the profile to user accounts and user groups. Android users are prompted to enter the password that is displayed on the screen.