Skip to main content

March 26, 2026 Archived

ACC Certificate Integration Workflows

Certificates are used to authenticate communication between the Workspace ONE UEM console and AirWatch Cloud Connector. In on-premises deployments, data and traffic between AWCM and AirWatch Cloud Connector is encrypted and signed.

How Certificates are Generated

  1. You enable the AirWatch Cloud Connector and then generate certificates for Workspace ONE UEM and AirWatch Cloud Connector.
    • Both certificates are unique to the group selected in the Workspace ONE UEM console and reside on the Workspace ONE UEM server.
    • Both certificates are generated from a trusted Workspace ONE UEM root.
  2. You install AirWatch Cloud Connector. The AirWatch Cloud Connector certificate that Workspace ONE UEM generates is automatically bundled and installed with AirWatch Cloud Connector.

How Data is Routed (On-Premises only)

  1. Workspace ONE UEM sends requests to AWCM. Requests are SSL encrypted using HTTPS.
  2. The AirWatch Cloud Connector queries AWCM for Workspace ONE UEM requests. Requests are SSL encrypted using HTTPS.
  3. All data is sent through AWCM.

The AirWatch Cloud Connector configuration trusts only messages signed from the Workspace ONE UEM environment. This trust is unique per group.

Any additional AirWatch Cloud Connector servers set up in the same Workspace ONE UEM group as part of a highly available (HA) configuration are issued the same unique AirWatch Cloud Connector certificate. For more information about high availability, refer to the Recommended Architecture Guide, available at Omnissa Product Documentation.

How Data is Secured (On-Premises only)

The Workspace ONE UEM server sends each request as an encrypted and signed message to the AWCM.

  • Requests are encrypted using the unique public key of the AirWatch Cloud Connector instance. Only AirWatch Cloud Connector can decrypt the requests.
  • Requests are signed using the private key of the Workspace ONE UEM server instance that is unique for each group. Therefore, AirWatch Cloud Connector trusts the requests only from the configured Workspace ONE UEM server.
  • Responses from AirWatch Cloud Connector to the Workspace ONE UEM server are encrypted with the same key as the request and signed with the AirWatch Cloud Connector private key.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…