MobiControl can request digital certificates on behalf of users and devices. MobiControl uses Certificate Templates to create certificates that are dynamic for each user and device.
Certificate Templates can be created based on:
Note: It is recommended that you enroll your devices with LDAP to effectively use Enrollment User or Enrollment User Email Address.
MobiControl supports the following certificate protocols:
To access Certificate Authorities, go to the All Platforms tab and then the Servers tab. Under Global Settings, open Certificate Authorities by clicking the wrench.
In the Certificate Authorities dialog,
Once a Certificate Authority has been configured with Certificate Templates, you can now send those certificates to your devices. Use a profile to assign certificates to your devices.
ADCS supports PKI and SCEP configuration types.
| Setting | Description |
|---|---|
| Name | Enter a name for your certificate authority. |
| Protocol | Choose which protocol MobiControl uses to communication with the Certificate Authority. Options are
|
| Enrollment URL | Enter the URL that received after installing the Certificate Enrollment Web Service. |
| Policy URL | Enter the URL received after installing the Certificate Enrollment Policy Web Service. |
| Trusted Root Certificate | If the Certificate Authority has a self-signed certificate, upload the root certificate here. |
| Enrollment Certificate | Upload the enrollment agent certificate. The enrollment agent certificate is used to sign certificate requests to the ADCS server and is explicitly trusted to request certificates on behalf of other users, for example, the device owner in MobiControl. |
| Authentication Type | The authentication type to communicate with the Certificate Authority. Options are
|
| Authentication Credential Certificate | Upload an Authentication Credential Certificate.
Note: Only available when Certificates is the selected Authentication Type. |
| Username | The username of the account to communicate with the Certificate Authority.
Note: Only available when Username/Password is the selected Authentication Type. |
| Password | The password of the account to communicate with the Certificate Authority.
Note: Only available when Username/Password is the selected Authentication Type. |
| Cloud Link Agent | Enter the client certificate that you use to authenticate to the Cloud Link Agent
Note: This option is only applicable to MobiControl Cloud customers. |
SCEP can only be used on iOS devices.
| Setting | Description |
|---|---|
| Name | Enter a name for your certificate authority. |
| Use SCEP Client | When enabled, your certificate authority uses a SCEP client. |
| Use Static Challenge | When enabled, a static challenge is used when devices request new certificates. When disabled, a Dynamic challenge is used. Every time a device requests a certificate, a new challenge will be issued. |
| Service URL | Enter the URL received after installing the Certification Authority Web Enrollment role service. |
| Challenge URL | Enter the URL received after installing the Network Device Enrollment role service. |
| Static Challenge | Enter the Static Challenge key here.
Note: Only applicable if Use Static Challenge is enabled. |
| Thumbprint | Enter the thumbprint for your certificate. |
| Username | The username of the account to communicate with the Certificate Authority. |
| Password | The password of the account to communicate with the Certificate Authority. |
| Retries | The number of times a device attempts to obtain a certificate. |
| Retry Delay | The timeout delay between each retry (in seconds). |
| Cloud Link Agent | Enter the client certificate that you use to authenticate to the Cloud Link Agent
Note: This option is only applicable to MobiControl Cloud customers. |
| Setting | Description |
|---|---|
| Name | Enter a name for your certificate authority. |
| Service URL | The URL provided by Entrust for certification services. |
| Username | The user name used to authenticate. |
| Password | The password used to authenticate. |
| Setting | Description |
|---|---|
| Name | Enter a name for your certificate authority. |
| Service URL | The URL of the Certificate Authority services. |
| Use Static Challenge | When enabled, a static challenge is used when devices request new certificates. When disabled, a Dynamic challenge is used. Every time a device requests a certificate, a new challenge will be issued. |
| Use SCEP Client | When enabled, your certificate authority uses a SCEP client. |
| Static Challenge | Enter the Static Challenge key here. A static challenge must be used if certificates are going to be issued to more than one device.
Note: Only applicable if Use Static Challenge is enabled. |
| Thumbprint | Enter the thumbprint for your certificate. |
| Retries | The number of attempts a device can make to get a certificate from the SCEP server. |
| Retry Delay | The timeout delay between each retry (in seconds). |
Certificate Templates allow MobiControl to create dynamic certificates based off of User enrollment or device authentication. To create a Certification Template, click Add beside the Templates section of the Certificate Authorities dialog window.
| Setting | Description |
|---|---|
| MobiControl Template Name | Enter a name for you Certificate Template. |
| Subject Name | The subject name used to create certificates. Clicking the cog beside here allows us to choose MobiControl Macros. Here we can choose if the subject name is an Enrolled User Principal Name, User Domain, User Username, User email or a Device Name, MAC Address, Serial Number or Platform. |
| Alternative Subject | Administrator can add additional subject alternative name for certificate template. The various options available are:
|
| Certificate Target | Here we can choose if the certificate will be issued to a device or a user. Choosing Device allows us to choose if the certificate is provisioned to authenticated users only and to preserver the private key. If we choose User both those options will be selected by default, and we cannot unselect them. Using User will offer the best security. |
| Provision Certificate to Authenticated Users Only | When enabled, only authenticated users have access to the certificate. |
| Certificate Usage | Choose whether the certificate will be for Signing, Encryption or Signing and Encryption. |
| Key Size | Choose the size of the key:
|
| Key Protection | Determines the level of protection for your key. Options are:
|
Note
When testing the functionality of Certificate Templates, ensure that the default template is used for simplicity. If a custom template must be used, ensure the following: In the Template properties, under Issuance Requirements, set Authorize Signatures to 1. For Policy type required in signature, select Application Policy. For Application Policy, select Certificate Request Agent.