You configure certificate authentication to allow clients to authenticate with certificates on their Android devices for single sign-on to the Workspace ONE Intelligent Hub app.
An X.509 certificate uses the public key infrastructure (PKI) standard to verify that a public key contained within the certificate belongs to the user.
To enable signing in using certificate authentication, you must upload the root certificates and intermediate certificate to the Omnissa Access service.
Configuring certificate authentication for Android Mobile SSO involves the following tasks:
- Certificate authority setup: Upload the root and intermediate CA certificates to the Omnissa Access service so that Android devices can be authenticated.
- Revocation checking (optional): Configure CRL or OCSP checking so that revoked certificates can no longer be used to authenticate.
- Mobile SSO for Android authentication method configuration: Configure the Mobile SSO (for Android) authentication method under Integrations > Authentication Methods, including the user identifier search order and revocation settings, then associate it with the built-in identity provider.
- Access policy rule: Add the Mobile SSO (for Android) authentication method to the Omnissa Access default access policy.
Was this page helpful?