Import certificate to Android 8.1 devices (Zebra TC51/56/MC33)

Solved Locked
G
Guenniko
iee1911

Hello All,

im newbie with mobicontrol and i looking for the best way to provide an SSL certificate to our devices.

We use TC51/56/MC33 with Android 8.1 with Enterprise Browser 3.0.0.1

Agent for non-gms 14.3.3.1038 for GMS 14.3.0.1000

Our mobicontrol version is 15.0.1.1181

The idea whas to use an script created with MCStudio and a profile. 

The script look like it:

    certimport -cert "filepath (path where the file comes from ;Server or Soti?)" -ctype CERT

What is your proposal for import the certificate?

Thank you 

Guenniko

Edited 5 years ago
Android
ANSWERS
ST
Shawn T
5 years ago

To install certificates you need to assign a device administrator password. This can be done by adding an authentication configuration to your profile.

Solution
MD
Matt Dermody Diamond Contributor
5 years ago

There is a native Certificate Profile option?

G
Guenniko
5 years ago

Hi Matt,

thank you for reply. 

What you mean with nativ Option? Profile for every device? I  have this certificate on which way we import them to the devices is complet open. It is for all devices the same.

Guenniko

J
Joakim
5 years ago

I guess what Matt means is that you can use MobiControl to create a Profile with a Configuration Item "Certificates" in order to import what you you need to all the devices.

 

One benefit from this is that you can create profiles for each model and filter this on model type or similar. The handling of certificates is much easier then utilizing scripts to perform the activities needed.

MD
Matt Dermody Diamond Contributor
5 years ago

Yes exactly! I would start with trying to use the natively exposed Profile option and if it doesnt do what you expect then you can try something more complex with scripting or even Zebra MX. 

G
Guenniko
5 years ago

Hello Matt hello Joakim,

thank you for this hint with the config. I will try during the week.

Thank you for your help

Guenniko

G
Guenniko
5 years ago

Hello,

i try to create the profile. But i got the message that "Multiple certificate PFX files not supported". We use an certificate.p7b file.

I google and search for supported formats but i cant find. Can you tell me which format can/must be used ?

Guenniko

MD
Matt Dermody Diamond Contributor
5 years ago

You may need to first confirm what formats are even supported by the Android OS before determining if you can distribute and install the certificate from an EMM. I am not familiar with the .p7b format and I am thinking it may need to be converted to something supported like a .crt with a tool like openSSL. 

Are you able to manually install the .p7b cert on the device from the security menu of settings? If not then I don't think you'll be able to push it from SOTI in that format either. 

G
Guenniko
5 years ago (edited 5 years ago)

Hi Matt,

we convert it into an cert.pem and Soti accept and read the certificate.

Now i need an additional administrator account for install it? When i add the account in the profil it works in the back or the Passphrase need to add during install?

I think i have a big backlock about the processes and structure in Soti

I will try it on next monday when im back in office 

Günter

G
Guenniko
5 years ago

Thank you to all for the support it works.

Have a nice week