Skip to main content

13 gennaio 2026

Secure Memcached

With the release of Workspace ONE UEM 2410, two additional supplementary configurations were introduced. These options can be configured during the Memcached installation process and are designed to strengthen the security of Memcached communications through encryption and authentication. Each of the following configurations can be applied independently or in combination. Note that implementing any configuration changes will require a service restart.

Use this information to enable and maintain Memcached security configurations.

SSL Encryption

Secure Sockets Layer (SSL) encryption configuration ensures that the communication between Workspace ONE UEM and the caching server are encrypted. This encryption is secured with a certificate credential which must be trusted on both the caching server as well as all Workspace ONE UEM service endpoints.

The certificate used for communication will be entered as part of the installation of the caching service. There is no requirement to upload it to the Workspace ONE UEM Console (application) or deploy it to devices. However, any certificate used during the installation of Memcached must include a DNS name that matches the value specified in the Host field of the Workspace ONE UEM Console and be in the personal and trusted root store of all Workspace ONE UEM application servers.

Note: Enabling this configuration updates the Memcached listener port from the default value of 11211 to 11213. To ensure successful integration of Memcached nodes within Workspace ONE UEM, this port change must also be reflected on the Memcached Configuration page.

Examples:

  • If specifying an IP address such as 10.10.10.10, the certificate’s DNS name must be 10.10.10.10.

  • If specifying a fully qualified domain name (FQDN) such as memcached.omnissa.com, the certificate must be issued to that exact FQDN.

    This requirement is essential to ensure proper TLS validation for each connection.

Enable TLS options

SASL Authentication

Simple Authentication and Security Layer (SASL) Authentication configuration adds an additional security layer of username/password authentication to all caching servers. This configuration is enabled and will prompt for username and password. Username and password set at the console level and used for all communications at the caching endpoint. After configuration in the console is complete, ensure that the caching install is running using the same username and password information.

EnableSASL Authentication options

Notes:

  • Any modifications to these configurations require a reinstallation of the Memcached server. During reinstallation, ensure the proper options are selected as both the certificate for SSL and the username/password for SASL are entered. Restart all services after modification of any of these configurations and the subsequent reinstallation.

  • When TLS and SASL are enabled, the Memcached Monitor Service will no longer work. TLS and SASL are not natively supported by the monitoring service.

Maintenance and Rotation

Maintenance and rotation of certificates and password are executed by re-running the Memcached installer.

Note: Omnissa will be releasing a supplementary tool containing the password and certificate rotation functions to ease impact from these regular maintenance activities.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…