Skip to main content

2026 年 8 月 21 日

Certificate-Based Authentication (CBA) Setup for Repositories

Client Certificate-Based Authentication (CBA) is a security mechanism that uses digital certificates to authenticate a user's identity or a device. It is a secure way of authentication compared to Basic authentication since it is not prone to MITM attack. Kerberos authentication requires Certificate Authority and Authentication Agency along with Certificate signing provider.

Step 1: Setup the AD Server

  1. Configure Certificate Authority on the AD Server.
  2. In the Certificate Authority add-in (certsrv), create the certificate template with the required rules the certificate templates.
  3. Create a service user (master user) in the AD users which authenticates on behalf of the user accessing the resource.
  4. Set the Service Principal Name (SPN) to the user using the setspn command. The service user acts as an admin user.
  5. Register the repository server using the setspn command.

Step 2: Setup on the Workspace ONE UEM Console

1. Configure the Directory Services

For more information, see Directory Service Settings.

2. Configure Certificate Authorities

For more information, see Certificate Authorities Settings.

3. Enable CBA profile

There are two ways to enable CBA for Content app.

Using CBA with PIV-D

  1. Create Credentials SDK profile with Credential Source as Defined Certificate Authority.

  2. Enter the Certificate Authority and Certificate Template.

  3. Save the changes.

    CBA with PIV-D

  4. Assign this profile to PIV-D public app.

Using CBA with Integrated Authentication (IA)

  1. Go to Apps > Settings and Policies > Settings > Custom Settings.

  2. Set the KVP NotUsePIVDForCBA to true.

  3. On Security Policies > SDK Settings, enable Integrated Authentication.

  4. Add the Credential Source as Defined Certificate Authority and enter the Certificate Authority and Certificate Template.

    CBA with IA

  5. Save the changes.

4. Configure Content Gateway

Enable the cross-domain KCD authentication and upload the certificate. For more information, see the description for Certificate Authentication on Content Gateway Settings.

Content Gateway Config

5. Configure the Repository

  1. Add the repo with the URL. Ensure that the service user has access to the repository.
  2. Enable the Content Gateway that has the CBA settings enabled.
  3. Enable Use Derived Credentials option.
    For example, consider configuring repository for NFS.
    Content Repository for CBA
  4. Save the repository.

Step 3: Configure the Device

Option 1: CBA with PIV-D

  1. Login to PIV-D using Hub or Standalone mode.
  2. Select the provider and create a PIN.
  3. Login to the Content app.
    • For iOS only: While accessing the repo on Content, you are prompted to enter the PIN created in PIV-D.
  4. Access the repository.

You can now view/download/upload the files from Content using the repository.

Option 2: CBA with Integrated Authentication (IA)

  1. Login to the Content app using Hub or Standalone mode.
  2. Access the repository.

You can now view/download/upload the files from Content using the repository.

このページは役に立ちましたか?

このトピックについてフィードバックを送信

このトピックは役に立ちましたか?

個人情報や機密情報は入力しないでください。

リンクを生成しています…