Skip to main content

August 11, 2026

Using Workspace ONE UEM Certificate Authority for Kerberos Authentication

You can use the Workspace ONE UEM Certificate Authority instead of the Active Directory Certificate Authority to set up single sign-on with built-in Kerberos authentication to Workspace ONE UEM managed iOS 9 or later mobile devices. You can enable Workspace ONE UEM Certificate Authority in the Workspace ONE UEM console and export the CA issuer certificate for use in the Omnissa Access service.

The Workspace ONE UEM Certificate Authority is designed to follow Simple Certificate Enrollment Protocol (SCEP) and is used with Workspace ONE UEM managed devices that support SCEP. Omnissa Access integration with Workspace ONE UEM uses the Workspace ONE UEM Certificate Authority to issue certificates to iOS 9 or later mobile devices as part of the profile.

The Workspace ONE UEM Certificate Authority issuer root certificate is also the OCSP signing certificate.

Enable and Export the Workspace ONE UEM Certificate Authority

When Omnissa Access is enabled in Workspace ONE UEM, you can generate the Workspace ONE UEM issuer root certificate and export the certificate for use with the Mobile SSO for iOS authentication on managed iOS 9 or later mobile devices.

Procedure

  1. In the Workspace ONE UEM console, navigate to System > Enterprise Integration> Omnissa Access.

    To enable Workspace ONE UEM Certificate Authority, the organization group type must be Customer.

    Tip: To view or change the group type, navigate to Groups & Settings, Groups > Organization Groups> Organization Group Details.

  2. Click Configuration.

  3. In the CERTIFICATE section, click Enable.

    This page displays the issuer root certificate details.

  4. Click Export and save the file.

What to do next

In the Omnissa Access console, configure Kerberos Authentication in the built-in identity provider and add the certificate authority issuer certificate.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…