Zebra TC51 not enabling network interfaces before PIN has been entered. (Android 8)

OD
Ole, Daugaard
Twise I/S

Hi,

Any suggestions as to why Zebra devices wont enable network interfaces before a PIN has been entered? 

We are requiring a device PIN due to a certificate profile on the device. However when soft resetting the device, we are prompted for device pin (naturally). However the network interfaces are not enabled until the PIN has been entered, thus effectively cutting of a branch for the mobicontrol administrator. (The devices still have an administrative WPA2 network available).

This is not the case for Samsung devices, they will activate interfaces to the network just fine before entering PIN.

Any suggestions or workarounds?

6 years ago
Android
ANSWERS
MD
Matt Dermody Diamond Contributor
6 years ago

Which Pin prompt are you seeing? Is it the Secure Startup Pin or the default Lockdown screen Pin?

OD
Ole, Daugaard
6 years ago

That would be the Secure Startup Pin, i.e. the device pin itself. Not related to the lockdown. So basically before you can access the Android OS GUI, it prompts and after entering the device will make Android available.

JJ
Jim J
6 years ago

I have also seen this on the TC77. We use NetMotion and it would not connect until the device PIN (not Secure Startup) was entered. The explanation that that I received was that Android locks the System Certificate Store until the PIN is entered on a reboot. Since the System Certificate Store is locked, the cert can't be used to authenticate on the network.

In our environment, we solved the problem by using the NetMotion Certificate Profile configuration. Using that method, NetMotion stores the required certificate in a private certificate store that they are able to access because it is not locked by the OS.

OD
Ole, Daugaard
6 years ago

Arh, thanks Jim!

Did you also test if regular WPA2 network was prevented, i.e. like as if the actual network interfaces was inactive until the PIN was entered?

That it prevents all network interfaces from starting up is what puzzles me completely. But regardless I could look into whether I'd be able to install the cert in the private certificate store on Device Owned AE enrolled devices.

Thanks again :-)