Add and manage a client certificate for a user account
- In the management console, on the menu bar, clickUsers > Managed devices.
- Search for and click a user account.
- Do any of the following:TaskStepsAdd a client certificate to a user accountYou can add a client certificate to an individual user account and send the certificate toBlackBerry Dynamicsenabled devices or other managediOSandAndroiddevices. Add client certificates to user accounts when users' devices need certificates for S/MIME or client authentication and the certificate can't be sent to devices via a user credential profile or SCEP profile. The client certificate must have a .pfx or .p12 file name extension. You can send more than one client certificate to devices. You can also use user credential profiles to upload certificates for individual users. User credential profiles can be associated with aWi-Fi, VPN, or email profile.
- In theIT policy and profilessection, click .
- ClickUser certificate.
- Type a description for the certificate.
- In theApply certificate tosection, select one of the following:
- Other managed devices: Choose this option to send the certificate toiOSandAndroiddevices for all supported uses other than forBlackBerry Dynamicsapps.
- BlackBerry Dynamics enabled devices: Choose this option to send the certificate to devices to use withBlackBerry Dynamicsapps.
- In theCertificate filefield, clickBrowse. Navigate to and select the certificate file.
- If you selectOther managed devices, in thePasswordfield, type a password for the certificate. ForiOSdevices, a password is required. ForAndroiddevices, you do not have to provide a password if the device is running the latest version of theUEM Client. If you don't set a password, the user must enter the device password.
- ClickAdd.
- Configure the time to live for client certificates. The default time to live before the client certificates are removed is 24 hours.
- On the menu bar, clickSettings > General settings > Certificates.
- Specify the time to live for PKCS#12 certificates on the server.
Renew or remove aBlackBerry Dynamicscertificate for a user accountYou can send a command to a user's device to request certificate renewal from the CA. You can also remove aBlackBerry Dynamicscertificate from a user's device. If you remove a certificate, theBlackBerry DynamicsPKI connector sends a notification to the CA that the certificate is no longer in use, but the certificate is not automatically revoked.In theUser certificatessection, perform one of the following actions:- Click to request certificate renewal from the CA.
- Click to remove the certificate from the user's devices.
To remove anEntrustsmart credential from a device, the user must also deactivate the smart credential in theBlackBerry UEM Client.Add a client certificate to a user credential profileYou can upload certificates for individual users to a user credential profile. Users can also upload their certificate to the user credential profile usingUEM Self-Service. Uploading certificates to user credential profiles is supported foriOSdevices and forAndroid Enterprisedevices.The client certificate must have a .pfx or .p12 file name extension. If you or a user uploads a new certificate to the user credential profile, it replaces the existing certificate on the users devices.Before you begin:- Assign the user credential profile to users.
- In theIT policy and profilessection, beside the user credential profile, clickAdd a certificate.
- ClickBrowse. Navigate to and select the certificate.
- Type the password for the certificate. ForiOSdevices, the password is required. ForAndroiddevices, you do not have to provide the password inUEMif the device is running the latest version of theUEM Client. If you don't specify the password, the user must enter the device password.
- ClickAdd.
Change a client certificate for a user credential profileThe new certificate will replace the existing certificate on the device.- In theIT policy and profilessection, beside the user credential profile, clickUpdate.
- ClickBrowseto locate the certificate.
- Type the password for the certificate. ForiOSdevices, the password is required. ForAndroiddevices, you do not have to provide the password inUEMif the device is running the latest version ofUEM Client. If you don't specify the password, the user must enter the device password.
- ClickSave.