Certificates impose a Screen Lock password

NL
Nicolas LE BIHAN
SYSTEME U CENTRALE NATIONALE

Hello,

One of my projects uses Samsung tablets. I need to configure certificates with a SOTI profile. A configuration with a SOTI certificates imposes an password for screen lock. 
Is it possible to bypass this requirement ? For example ZEBRA bypasses this obligation.

For information I use a Samsung Active PRO tablet 
Android version : 11
Agent Version : AE 15.1.2.1075
Console Version : 15.4 

3 years ago
SOTI MobiControl
ANSWERS
MD
Matt Dermody Diamond Contributor
3 years ago

In my experience having an Authentication Profile configured with an admin password bypasses this requirement. I believe it has something to do with that password being used to initialize and then unlock the keystore where certificates are stored instead of relying on the device password/screen lock that is set. Then again I have this working on Zebra devices and have not tried with Samsung so it may only be a Zebra thing like you have mentioned. 

TB
TJ Bukoski
3 years ago

Matt, you are 100% correct here, the passcode is required to secure the keystore for securing certificates. Most Android devices use the lock screen passcode to do this. Zebra seems to have separated the lock screen passcode from the keystore passcode and SOTI has taken advantage of this feature.

K
KCMOD@SOTI
3 years ago

Hello Nicolas,

Thank you for posting on SOTI Central!
Please kindly let me know if responses from Matt and TJ helped to answer your question and if you have any other questions?
If so, please mark this post as solutioned.

Matt and TJ, thank you for your input!

Regards,
Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net

NL
Nicolas LE BIHAN
3 years ago

Hello,

@KCMOD@SOTI No, Matt and TJ answers don't help me to answer my question.  They confirmed my problem and my tests on Zebra terminals. 
As a reminder, my question is: Is it possible not to impose the configuration of a password if a SOTI profile installs certificates on a Samsung device?

K
KCMOD@SOTI
3 years ago

Hello Nicolas,

Thank you for your reply.

Please note that with Android 10 and above it should not be required to have a pin on the device when installing the Certificates payload through MobiControl.
In the version of the agent that you are using for the project (v15.1.2) most likely is an issue.

Can you please try upgrading the device agent to v15.1.4 and test deploying certificates without a password on the device?
Please see the below release notes as well, you will find the fix for the issue in the second JIRA listed in the screenshot:

 
Please let me know how it goes and if you nave any questions.
 
Regards,
Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net