If you want to use certificate-based authentication, you must first create a shared certificate profile, SCEP profile, or user credential profile.
In the management console, on the menu bar, click Policies and profiles > Networks and connections > Single sign-on.
Click .
Type a name and description for the profile.
In the Kerberos section, click .
In the Name field, type a name for the configuration.
In the Principal name field, type the name of the Kerberos Principal, using the format <primary>/<instance>@<realm> (for example, user/admin@blackberry.example.com).
In the Realm field, type the Kerberos realm in uppercase letters (for example, EXAMPLE.COM).
In the URL prefixes field, type the URL prefix for the sites that you want devices to authenticate with. The prefix must begin with http:// or https://, and can include wildcard values (*) (for example, https://www.blackberry.example.com/*).
If necessary, click to add additional URL prefixes.
If you want to limit the configuration to specific apps, click + beside App identifiers and specify the app bundle ID. You can use a wildcard value (*) to match the ID to multiple apps (for example, com.company.*).
If necessary, click to add additional URL prefixes.
If you want iOS devices to use certificate-based authentication, in the Credentials drop-down list, click Certificate, SCEP, or User credential. In the drop-down list, click the certificate profile that you want to use.