Skip to main content

Send Derived Credentials from the Console to Android Devices

Add and publish the Workspace ONE PIV-D Manager for Android app to devices as a public app. The app receives the derived credential certificates from the console so that the device can use them.

Procedure

  1. Navigate to Resources > Apps > Native > Public and select Add Application.

    The Managed By text box displays the organization group where the app is uploaded.

  2. Select Android for the Platform.

  3. To find the application, select Search App Store from the Source text box.

  4. To find the application in the app store, enter Workpace ONE PIV-D Manager in the Name text box.

  5. Select the application from the app store result page.

    The Add Application window displays. Adding information is optional.

  6. To move to the deployment section, select Save & Assign.

    You assign the app to devices and add optional app config parameters in the deployment section.

  7. Select the Assignment tab and Add Assignment.

  8. Enter a group that includes the devices that use your derived credential solution for Select Assignment Groups.

  9. Optional: Enable Application Configuration and enter the listed Configuration Key and the Value pairs. To insert lines, use the Add button.

    App config parameters perform some manual configurations for the user on the device but they are not required for Workspace ONE PIV-D Manager to work.

    Common App Config Key-Value Pairs
    Configuration Key Value Type Configuration Value Description
    CertificateExpiryWarningStringYour custom warning message for when a certificate is about to expire.If nothing is manually set, then our default warning message is displayed.
    CertificateExpiryWarningPeriod Integer Enable = Any numerical value greater than 0 Disable = 0The default value is 30 days when nothing is manually set.
    ConnectorAppNameString Select an application name that can be used by a back end connector to Workspace ONE UEM. To select a lookup value from the list or enter fixed text such as "Workspace ONE PIV-D", click +. This configuration key is only supported by the Intercede provider.
    ConnectorDeviceIdentifierString Select a device identifier that can be used by a back end connector to Workspace ONE UEM. To select a lookup value, such as {DeviceUid}, from the list, click +. This configuration key is only supported by Entrust and Intercede providers.
    EnableEntrustBluetoothLoginBoolean True = On False = OffWhen you enable this value, the PIN policy defined in the Entrust system is honored instead of what is defined here.
    EnableKeyChainInstallationBoolean True = On False = OffEnables PIV-D Manager to install credentials directly to the Android Keystore through the Android KeyChain interface on unmanaged devices.
    EnableManualCertificateImportBoolean True = On False = OffEnables integrations with XTec to import certificates from web browser downloads using the download portal website for customers.
    EnablePDFSigningBoolean True = On False = OffEnables apps like Workspace ONE Boxer or Adobe Acrobat Reader to sign a PDF document using the derived credential in Workspace ONE PIV-D Manager Newly signed documents are encrypted and newly saved documents will be available in the PIV-D App storage. The default configuration is set to True.
    PIVDConfigArray 0 = Off 1 = OnWorkspace ONE PIV-D Manager prompts the end user for an app token from Self Service Portal before letting them proceed with fetching an SDK profile and certificate. This feature only works when the PIVDProvider configuration key value is 5 (Workspace ONE UEM).
    PIVDInstructionsStringThe instructional text for the end user.A brief single string instruction for the end user to prepare them for using the app to activate/provision/import derived credentials from the provider.
    PIVDPromptForPINBoolean True = On False = OffWorkspace ONE PIV-D Manager prompts the end user for the PIN even if you enable SSO.
    PIVDProviderInteger 1 = Entrust 2 = Intercede 3 = Purebred 4 = XTec 5 = Workspace ONE UEM 6 = YubiKey 7 = AuthentX ID by XTecThis numeric value corresponds to a given provider. Workspace ONE UEM sends the value to the app to pre-configure the provider for the assigned end users.
    Android App Config Key-Value Pair
    KeyValue TypeDescription
    PinDisallowDuplicateBooleanSetting to True checks for duplicate characters next to each other in the pin protecting the certificate store.
    PinDisallowSequentialBooleanSetting to True checks for a sequence of characters going up or down in value (123, 321, abc) in the pin protecting the certificate store.
    PinLengthMinimumIntegerThe minimum character length for the pin protecting the certificate store. For iOS devices, the minimum required PIN length is six characters.
    PinLowercaseMinimumIntegerThe minimum number of lowercase characters for the pin protecting the certificate store.
    PinNumbersMinimumIntegerThe minimum number of number characters for the pin protecting the certificate store.
    PinSpecialCharMinimumIntegerThe minimum number of special characters for the pin protecting the certificate store. Supported characters: ~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/
    PinUppercaseMinimumIntegerThe minimum number of uppercase characters for the pin protecting the certificate store.
  10. Select Add to assign the app to the devices in the assignment group and then save and publish Workspace ONE PIV-D Manager as a managed application.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…