Certificate Authorities


MobiControl can request digital certificates on behalf of users and devices. MobiControl uses Certificate Templates to create certificates that are dynamic for each user and device.

Certificate Templates can be created based on:

Note: It is recommended that you enroll your devices with LDAP to effectively use Enrollment User or Enrollment User Email Address.

Certificate Authorities

MobiControl supports the following certificate protocols:

To access Certificate Authorities, go to the All Platforms tab and then the Servers tab. Under Global Settings, open Certificate Authorities by clicking the wrench.

Adding a Certificate Template

In the Certificate Authorities dialog,

  1. Click the New button and select either ADCS, Entrust, or Generic SCEP.
  2. Fill in the Mandatory fields. See the tables below for more information.

Once a Certificate Authority has been configured with Certificate Templates, you can now send those certificates to your devices. Use a profile to assign certificates to your devices.

ADCS

ADCS supports PKI and SCEP configuration types.

PKI

Setting Description
Name Enter a name for your certificate authority.
Protocol Choose which protocol MobiControl uses to communication with the Certificate Authority. Options are
  • HTTPS
  • DCOM
Enrollment URL Enter the URL that received after installing the Certificate Enrollment Web Service.
Policy URL Enter the URL received after installing the Certificate Enrollment Policy Web Service.
Trusted Root Certificate If the Certificate Authority has a self-signed certificate, upload the root certificate here.
Enrollment Certificate Upload the enrollment agent certificate. The enrollment agent certificate is used to sign certificate requests to the ADCS server and is explicitly trusted to request certificates on behalf of other users, for example, the device owner in MobiControl.
Authentication Type The authentication type to communicate with the Certificate Authority. Options are
  • Certificate
  • Username/Password
  • Kerberos
Authentication Credential Certificate Upload an Authentication Credential Certificate.

Note: Only available when Certificates is the selected Authentication Type.

Username The username of the account to communicate with the Certificate Authority.

Note: Only available when Username/Password is the selected Authentication Type.

Password The password of the account to communicate with the Certificate Authority.

Note: Only available when Username/Password is the selected Authentication Type.

Cloud Link Agent Enter the client certificate that you use to authenticate to the Cloud Link Agent

Note: This option is only applicable to MobiControl Cloud customers.

SCEP

SCEP can only be used on iOS devices.

Setting Description
Name Enter a name for your certificate authority.
Use SCEP Client When enabled, your certificate authority uses a SCEP client.
Use Static Challenge When enabled, a static challenge is used when devices request new certificates. When disabled, a Dynamic challenge is used. Every time a device requests a certificate, a new challenge will be issued.
Service URL Enter the URL received after installing the Certification Authority Web Enrollment role service.
Challenge URL Enter the URL received after installing the Network Device Enrollment role service.
Static Challenge Enter the Static Challenge key here.

Note: Only applicable if Use Static Challenge is enabled.

Thumbprint Enter the thumbprint for your certificate.
Username The username of the account to communicate with the Certificate Authority.
Password The password of the account to communicate with the Certificate Authority.
Retries The number of times a device attempts to obtain a certificate.
Retry Delay The timeout delay between each retry (in seconds).
Cloud Link Agent Enter the client certificate that you use to authenticate to the Cloud Link Agent

Note: This option is only applicable to MobiControl Cloud customers.

Entrust

Setting Description
Name Enter a name for your certificate authority.
Service URL The URL provided by Entrust for certification services.
Username The user name used to authenticate.
Password The password used to authenticate.

Generic SCEP

Setting Description
Name Enter a name for your certificate authority.
Service URL The URL of the Certificate Authority services.
Use Static Challenge When enabled, a static challenge is used when devices request new certificates. When disabled, a Dynamic challenge is used. Every time a device requests a certificate, a new challenge will be issued.
Use SCEP Client When enabled, your certificate authority uses a SCEP client.
Static Challenge Enter the Static Challenge key here. A static challenge must be used if certificates are going to be issued to more than one device.

Note: Only applicable if Use Static Challenge is enabled.

Thumbprint Enter the thumbprint for your certificate.
Retries The number of attempts a device can make to get a certificate from the SCEP server.
Retry Delay The timeout delay between each retry (in seconds).

Certificate Templates

Certificate Templates allow MobiControl to create dynamic certificates based off of User enrollment or device authentication. To create a Certification Template, click Add beside the Templates section of the Certificate Authorities dialog window.

Setting Description
MobiControl Template Name Enter a name for you Certificate Template.
Subject Name The subject name used to create certificates. Clicking the cog beside here allows us to choose MobiControl Macros. Here we can choose if the subject name is an Enrolled User Principal Name, User Domain, User Username, User email or a Device Name, MAC Address, Serial Number or Platform.
Alternative Subject Administrator can add additional subject alternative name for certificate template. The various options available are:
  • DNS Name
  • URL Name
  • Registered ID Name
  • User Principal Name
  • RFC822 Name
Certificate Target Here we can choose if the certificate will be issued to a device or a user. Choosing Device allows us to choose if the certificate is provisioned to authenticated users only and to preserver the private key. If we choose User both those options will be selected by default, and we cannot unselect them. Using User will offer the best security.
Provision Certificate to Authenticated Users Only When enabled, only authenticated users have access to the certificate.
Certificate Usage Choose whether the certificate will be for Signing, Encryption or Signing and Encryption.
Key Size Choose the size of the key:
  • 1024
  • 2048
  • 4096
  • 8192
Key Protection Determines the level of protection for your key. Options are:
  • Protected
  • Protected if Supported
  • Not Protected

Note

When testing the functionality of Certificate Templates, ensure that the default template is used for simplicity. If a custom template must be used, ensure the following: In the Template properties, under Issuance Requirements, set Authorize Signatures to 1. For Policy type required in signature, select Application Policy. For Application Policy, select Certificate Request Agent.

© SOTI Inc.
Contact us