Configure KCD for BlackBerry Dynamics apps
- Review the Prerequisites for configuring KCD for BlackBerry Dynamics apps.
- If you are configuring KCD for BlackBerry Docs, see Configuring Kerberos constrained delegation for the Docs service in the BlackBerry Enterprise Mobility Server content.
- To map the Kerberos service account to an SPN, on the Active Directory server, open the command prompt as an administrator and type the following, specifying the host server name, domain, and Kerberos service account. The Kerberos service account is the service account name under which the KCD service will be configured in UEM (gc.krb5.principal.name). This account does not need to be the same as the UEM service account, but can be.
setspn –s GCSvc/UEM <domain>\<Kerberos_service_account>For example:setspn –s GCSvc/UEM example.com\kcdadmin - Follow these steps to generate a new Kerberos keytab file and set the Kerberos account password:
- On the KDC server, open a command prompt.
- Run the following command and specify the appropriate values:
ktpass /out outfilename.keytab /mapuser kerberos_account@REALM_IN_ALL_CAPS /princ GCSvc/UEM@REALM_IN_ALL_CAPS /pass kerberos_account_password /ptype KRB5_NT_SRV_HST /crypto AES256-SHA1In a multi-realm Kerberos environment, you must run thektpasscommand for each realm. It is a best practice to use unique keytab files for each realm. - Copy the new keytab file to every UEM server that you want to use the same KCD administrator account.
- Enable enumeration of Active Directory user objects group membership. For more information, see Appendix B: Privileged Accounts and Groups in Active Directory.
- On each UEM server, follow these steps to configure permissions for the UEM service account so that it can send user credentials to the Kerberos system (this is the same account that has the associated SPN):
- In the Microsoft Management Console, navigate to Local Security Policy > Local Policies > User Rights Assignments.
- Open the properties of Act as part of the operating system and click Add User or Group.
- Type the name of the service account and click OK.
- In the UEM management console, on the menu bar, click Settings > BlackBerry Dynamics > Global properties.
- Select the Use explicit UPN check box.
- Select the Enable KCD check box.
- Click Save.
- On the menu bar, click Settings > BlackBerry Dynamics > Properties and click the server name.
- In the Fully qualified name for the KDC (gc.krb5.kdc) field, type the fully qualified name for the KDC. It usually corresponds to the FQDN of an Active Directory domain controller.
- In the Location of keytab file (gc.krb5.keytab.file) field, type the location of the keytab file. Use forward slashes in the path name.
- In the Service account name under which KCD service is running (gc.krb5.principal.name) field, type the service principal name.
- In the Realm - Active Directory (gc.krb5.realm) field, type the name of the Active Directory realm in all uppercase letters.
- In the Location of krb5.config file on GC server (gc.krb5.config.file) field, type the location of the krb5.conf file.For more information about the requirements for the krb5.conf file, see Prerequisites for configuring KCD for BlackBerry Dynamics apps.
- Click Save.