Lesson 16 - Integrating with Certificate Authorities


  • Configuring Certificate Authorities
  • Configuring Certificate Templates


 AirWatch supports certificate integration to offer superior levels of security, stability, and authentication for your mobile device fleet. Certificate Authority (CA) integration provides advantages such as cross-platform scalability, high security, and multi-functionality in the form of encryption, message signing, and authentication. The AirWatch solution not only ensures safe and secure certificate management, but also automates the management process through the certificate lifecycle including: issuing, managing, renewing, and revoking as needed. AirWatch supported CA's include: Microsoft ADCS, Generic SCEP, Verisign MPKI, Symantec, OpenTrust CMS Mobile, Entrust, SecureAuth and RSA Certificate Manager. 


Configuring Certificate Authorities  

 Watch the Video!

To integrate with a Certificate Authority:

  1. Navigate to Devices > Certificates > Certificate Authorities 
  2. Select Add and enter a Name and Description that identifies the CA
  3. Select the desired Authority Type from the dropdown menu, and complete settings as required by the chosen authority type
  4. Select Save once all required fields have been completed


Configuring Certificate Templates  

 Watch the Video!

To configure a Certificate Template:

  1. Navigate to Devices > Certificates > Certificate Authorities > select the tab for Request Templates
  2. Select Add and enter a Name and Description to identify the template
  3. Select a Certificate Authority from the dropdown, and configure settings for the template to match those specified for the template in the CA
  4. Select Save once all required fields have been completed


Once the certificate template has been created and associated to a Certificate Authority, it can now be deployed to devices via a profile. To deploy a certificate to a device:

  1. Navigate to Devices > Profiles > List View
  2. Select Add and choose a support platform, such as Android, iOS, or Windows Phone 8
  3. Complete information for the General tab in the profile, then select the Credential payload and click Configure (SCEP certificates can be deployed for iOS and OSX products via the SCEP payload)
  4. Select the Defined Certificate Authority and then choose the appropriate Certificate Authority and Certificate Template
  5. Click Save & Publish to deploy this profile to devices 



Have more questions? Submit a request


Article is closed for comments.