Create a user credential profile to use app-based certificates on iOS devices
iOS
devices- Ensure that the PKI app (for example, Purebred) is installed on users' devices.
- On the menu bar, clickPolicies and Profiles > Certificates > User credential.
- Click .
- Type a name and description for the profile.
- In theCertificate authority connectiondrop-down list, click the name of the app you specified when you connectedBlackBerry UEMto your PKI solution. If you are usingPurebred, select theBlackBerry UEM Client.
- To specify which certificate theBlackBerry Dynamicsapp will use, perform the following actions:
- In theKey usagesection, select the operations that the certificate supports.BlackBerry Dynamicsapps will only use certificates that have at least the specified key usage value set. For example, an encryption certificate may have a key usage value ofKey encipherment. An authentication certificate may have a key usage value ofDigital signature. A signing certificate may have a key usage value of bothDigital signatureandNonrepudiation.
- In theExtended key usagesection, select the functions that the certificate was issued for.BlackBerry Dynamicsapps will only use certificates if all selected extended key usage values are present in the certificate. Certificates can have additional extended key usage values.
- If the certificate was issued for purposes other than email, client authentication, or smart card login, selectAdditional Object ID usage, click and specify the OID for the key usage. For example, if the certificate will be used for server authentication, it may have the OID 1.3.6.1.5.5.7.3.1.
- BesideIssuers, click and type the issuer name.BlackBerry Dynamicsapps will only use a certificate if the specified issuer matches theOpenSSLshort-form OID in the certificate. You can copy this value from the issuer's certificate. Do not put spaces before or after the equal sign (=). For example:CN=Acme_cert SMIME,OU=Acme_Legal,O=Acme,C=Can CN=Acme_cert SMIME,OU=Acme_Legal,O=Acme CN=Acme_cert TLS
- If you want the device to delete expired certificates, selectDelete expired certificates.
- If you want the device to delete duplicate certificates, selectRemove duplicate certificates.
- ClickAdd.
- To allowBlackBerry Dynamicsapps to use certificates, on the menu bar, clickApps. Click theBlackBerry Dynamicsapp that you want to change, then on theSettings > BlackBerry Dynamicstab, select theAllow BlackBerry Dynamics apps to use user certificates SCEP profiles and user credential profilescheckbox.
- Assign the profile to user accounts and user groups.