The administrator can provision SCEP profiles to the work space so that devices can automatically enroll identity certificates. The administrator can control when these certificates are removed from the device (e.g. by unassigning, specifying validity period. The SCEP profiles should be align with SCEP profiles supported by iOS devices and BlackBerry 10 for consistency.
Support for auto-renew certificates before expiration, if the x-Platform OS supports this, is required. See business justification below.
Key Use Cases:
These certificates can then be used e.g. for
- cert based authentication on ActiveSync
- cert based authentication for mutual ssl
Business Justification:
Certificate based authentication is a critical use cases supported by competitive offerings.
BlackBerry response to Forrester EMM MQ Survey of 2014 included the following:
"Auto-Renew certificates before expiration" is not supported for iOS and "In Development" for Android.
This will help with consistency when cert based authentication is enabled on BlackBerry 10 devices with SCEP based certs so that the same method is also supported for the work space.