Sending client certificates to devices and apps using user credential profiles

User credential profiles allow devices to use client certificates obtained by the following methods:

  • Manually uploading certificates to the BlackBerry UEM management console or, in an on-premises environment, to UEM.
  • An established connection between UEM and your organization’s Entrust CA or OpenTrust CA.
  • For BlackBerry Dynamics apps on Android devices, certificates stored in the device native keystore.
  • For BlackBerry Dynamics apps, through an established BlackBerry Dynamics PKI connector connection.
  • For BlackBerry Dynamics apps, using an app-based PKI solution such as Purebred.

User credential profiles are supported on iOS and Android devices. App-based PKI solutions are supported for BlackBerry Dynamics apps on iOS and Android devices. Manually uploading certificates is supported for iOS, Android Enterprise, and Samsung Knox Workspace.

Alternatively, you can use SCEP profiles to enroll client certificates to devices. You can also upload certificates directly to a user account. The type of profile you choose depends on how your organization uses the PKI software, the types of devices your organization supports, and how you want to manage certificates.