The BES must be able to manage certificates for Android for Work devices, which includes
- the ability for an admin to assign user certificates (minimum PKCS#12 payloads) and CA certificates in the BES console to a user/group
- the ability to associate a certificate with a specific profile that it will be used with, e.g. a WiFi profile, a VPN profile or and ActiveSync profile
- the distribution of the certificates to the device upon assignment and the removal upon unassignment
- the ability for an admin to see that a certificate is assigned to a specific user
Note: at a minimum the Android for Work v2 has to be supported but ideally, the AfW v1 should also be supported to allow EAS cert based auth if available
Use case:
An enterprise wants to enable their device users to use Android for Work on AfW devices and use BES as their EMM service. They want to manage certificates as credentials and for trust validation.
Business Justification:
Android for Work is expected to be the unified approach to EMM on Android devices. BlackBerry needs to support AfW to remain relevant as an EMM vendor for Android.