Skip to main content

August 21, 2026

EJBCA

Workspace ONE UEM is flexible with PKI integration by being able to request certificates from either internal or external certificate authorities (CA). This article explains how to integrate with Enterprise Java Beans Certificate Authority (EJBCA) services to issue certificates for your Workspace ONE UEM MDM solution.

Important: If you select Key Recoverable as part of an EJBCA backed certificate configuration, then this defaults to the certificate private key generation taking place in the CA instead of within Workspace ONE UEM. In this scenario, it is important to understand your certificate renewal frequency to ensure the amount of certificates that are renewed daily can be supported by the CA infrastructure. Properly scaling the CA infrastructure and the certificate renewal period will keep daily certificate requests from exceeding your CA’s capacity.

Integrating with EJBCA

To have Workspace ONE UEM communicate with EJBCA for certificate distribution, you must have an EJBCA instance configured and ready to issue certificates. Then, configure Workspace ONE UEM to communicate with EJBCA using certificate based authentication. Once communication is successfully established, define how to deploy certificates to devices. Below are some of the examples of how EJBCA and Workspace ONE UEM can be configured.

  • Scenario 1: Workspace ONE UEM SaaS with EJBCA installed on-premises.
    Configuration showing the device enrolled with Workspace ONE UEM SaaS and EJBCA is installed on premises.
    1. Device enrolls with Workspace ONE UEM.
    2. Workspace ONE UEM requests certificate from EJBCA endpoint (optionally through the AirWatch Cloud Connector).
    3. The EJBCA endpoint delivers the certificate to Workspace ONE UEM (optionally through the AirWatch Cloud Connector).
    4. Workspace ONE UEM delivers the certificate to the device as part of an EAS, VPN, or WiFi profile.

If your EJBCA endpoint is public-facing, then it must be protected by a public SSL certificate. If you are using AirWatch Cloud Connector, then it needs to be configured to trust the root certificate installed on your EJBCA appliance.

  • Scenario 2: Workspace ONE UEM and EJBCA both installed on-premises.
    Configuration showing the devices enrolled with Workspace ONE UEM and EJBCA installed on premises.
    1. Device enrolls with Workspace ONE UEM.
    2. Workspace ONE UEM requests certificate from EJBCA endpoint (optionally through the AirWatch Cloud Connector).
    3. The EJBCA endpoint delivers the certificate to Workspace ONE UEM (optionally through the AirWatch Cloud Connector).
    4. Workspace ONE UEM delivers the certificate to the device as part of an EAS, VPN, or WiFi profile.

If your EJBCA endpoint is public-facing, then it must be protected by a public SSL certificate. If you are using AirWatch Cloud Connector, then it needs to be configured to trust the root certificate installed on your EJBCA appliance. See Configuring AirWatch Cloud Connector to trust EJBCA for more information.

Prerequisites

  • An EJBCA instance that is configured for certificate deployment.
  • Workspace ONE UEM console version 2310 or later.
  • If your EJBCA appliance is public-facing, it must be protected with a Public SSL Certificate. If you are using AirWatch Cloud Connector for enterprise integration, then it needs to be configured to trust the root certificate installed on your EJBCA appliance.

Procedure

  1. Generate an EJBCA certificate.

  2. Configure the CA and the request template in the Workspace ONE UEM console.

    1. Configure the CA.
      1. Navigate to Devices > Certificates > Certificate Authorities.
      2. Click Add and complete the following menu options.
        OptionDescription
        Authority TypeEJBCA
        Server URLEnter the URL of your EJBCA instance.

        This is the web endpoint that Workspace ONE UEM uses to submit requests and issue certificates.

        CertificateSelect to Upload the certificate from the location on your PC to which it has been saved.
        SANInclude one or more Subject Alternate Names (SANs) with the template. This is used for additional unique certificate identification. In most cases, this needs to match the certificate template on the server. Use the drop-down menu to select the SAN Type and enter the subject alternate name in the corresponding data entry field. Each field supports lookup values.
      3. Click Save.
  3. Configure Workspace ONE UEM profiles (payloads). Once either of these profiles is created, you can create additional payloads that the EJBCA certificate can use, such as Exchange ActiveSync (EAS), VPN, or Wi-Fi services.

    1. Navigate to Devices > Profiles > List View.
    2. Click Add.
    3. Select the applicable platform for the device type.
    4. Specify all General profile parameters.
    5. Select Credentials from the payload options and select Configure.
    6. Select Defined Certificate Authority from the Credential Source drop-down menu.
    7. Select the external EJBCA certificate you created previously.
    8. Select the request template for EJBCA you created previously. Saving and publishing the profile would deploy a certificate to the device. If you plan on using the certificate on the device for Wi-Fi, VPN, or email purposes, you should also configure the respective payload in the same profile to leverage the certificate being deployed.
  4. Optional: If you are using AirWatch Cloud Connector and the EJBCA appliance is not public-facing, then you need to ensure the AirWatch Cloud Connector configuration trusts the appliance.

    1. Open the EJBCA console certificate and view the Certificate Path tab.
      1. If multiple certificates are listed, they will need to be separated and added to the appropriate stores.
      2. The remaining steps address adding the root certificate to the Trust Root Store.
    2. Open MMC by searching for it using Windows search and launching the mmc.exe file.
    3. Navigate to File > Add/Remove Snap-in. The Add or Remove Snap-ins screen displays.
    4. In the left pane, select the Certificates snap-in. Select Add.
    5. Select Computer account as Snap-in source. Select Next.
    6. Select Local computer and then select Finish.
    7. Select OK.
    8. Expand the newly added Certificates tree.
    9. Expand the Trusted Root Certification Authorities folder.
    10. Right-click the Certificates folder here. Select All Tasks > Import.
    11. Proceed through the Certificate Import Wizard. You will be prompted to Browse. 12. Select the file of the root certificate used to generate the EJBCA Console certificate. Select Next.
    12. Select Place all certs in the following store and then select Next.
    13. Click Finish.
    14. Select all other intermediate and child certificates to add them to their associated stores within the Certificates tree.

Integration Tips and Troubleshooting

  • Verify ability to perform certificate authentication without Workspace ONE UEM.
    Remove Workspace ONE UEM from the configuration and manually configure a device to connect to your network server using certificate authentication. This should work outside of Workspace ONE UEM and until this works properly, Workspace ONE UEM will not be able to configure a device to connect with a certificate.

  • Verify ability to perform certificate authentication with Workspace ONE UEM.
    You can confirm that the certificate is usable by pushing a profile to the device and testing whether or not the device is able to connect and sync to the configured EAS, VPN, or Wi-Fi access-point. If the device is not connecting and shows a message that the certificate cannot be authenticated or the account cannot connect then there is a problem in the configuration. Below are some helpful troubleshooting checks.

  • If SSL TLS errors are received while creating a template.

    • This error can occur when you attempt two tasks.
      • Create a Workspace ONE UEM certificate template byselecting the Retrieve Profiles button.
      • Retrieve a certificate from the Workspace ONE UEM console from the SecureAuth certificate authority.
    • The troubleshooting technique that usually resolves this problem is adding the required server certificate chain in the console servers trusted root key store.
  • If the Workspace ONE UEM certificate profile fails to install on the device.

    • Inform Workspace ONE UEM Professional Services of the error and request they:
      • Turn on Verbose Mode to capture additional data.
      • Retrieve the web console log.
    • Workspace ONE UEM analyzes the log and works with customer to resolve the problem.
  • If the certificate is not populated in the View XML option of the profile.

    • Confirm that lookup values configured on the EJBCA certificate profile match the look up values in the Workspace ONE UEM console request template.
    • Confirm that lookup values in Workspace ONE UEM request template are actually populated in the user information being pulled from AD.
    • Confirm you are pointing to the right profile in EJBCA.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…