BlackBerry Dynamicsapps support both
KerberosPKINIT with PKI certificates and
KerberosConstrained Delegation. Kerberos PKINIT and
KerberosConstrained Delegation are distinct implementations of
Kerberos. You can support one or the other for
BlackBerry Dynamicsapps, but not both.
KerberosPKINIT, authentication occurs directly between the
BlackBerry Dynamicsapp and the
WindowsKey Distribution Center (KDC). User authentication is based on certificates that are issued by
Microsoft Active DirectoryCertificate Services. No additional programming is required by the app developer to use
KerberosConstrained Delegation, authentication is based on a trust relationship between the management server (
BlackBerry UEMand a KDC. The management server communicates with the service on behalf of the app.
For more information about how to configure the desired
UEM, including requirements and prerequisites, see Configuring Kerberos for BlackBerry Dynamics apps in the
UEM Administration Guide.