Credentials device policy 编辑

Credentials device policies point to a PKI configured in Endpoint Management. For example, your PKI configuration might include a PKI entity, a keystore, a credential provider, or a server certificate. For more information about credentials, see Certificates and authentication.

Each supported platform requires a different set of values, which are described in this article.

Note:

Before you can create this policy, you need the credential information you plan to use for each platform, plus any certificates and passwords.

To add or configure this policy, go to Configure > Device Policies. For more information, see Device policies.

iOS and tvOS settings

Device Policies configuration screen

Configure the following settings:

  • Credential type: In the list, click the type of credential to use with this policy, and then enter the following information for the selected credential:
    • Certificate
      • Credential name: Enter a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and navigating to the file’s location.
    • Keystore
      • Credential name: Enter a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and navigating to the file’s location.
      • Password: Enter the keystore password for the credential.
    • Server certificate
      • Server certificate: In the list, click the certificate to use.
    • Credential provider
      • Credential provider: In the list, click the name of the credential provider.
  • Policy settings
    • Remove policy: Choose a method for scheduling policy removal. Available options are Select date and Duration until removal (in hours)
      • Select date: Click the calendar to select the specific date for removal.
      • Duration until removal (in hours): Type a number, in hours, until policy removal occurs.
    • Allow user to remove policy: You can select when users can remove the policy from their device. Select Always, Passcode required, or Never from the menu. If you select Passcode required, type a passcode in the Removal passcode field. Not available for iOS.

macOS settings

Device Policies configuration screen

Configure the following settings:

  • Credential type: In the list, click the type of credential to use with this policy, and then enter the following information for the selected credential:
    • Certificate
      • Credential name: Enter a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and navigating to the file’s location.
    • Keystore
      • Credential name: Enter a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and navigating to the file’s location.
      • Password: Enter the keystore password for the credential.
    • Server certificate
      • Server certificate: In the list, click the certificate to use.
    • Credential provider
      • Credential provider: In the list, click the name of the credential provider.
  • Policy settings
    • Remove policy: Choose a method for scheduling policy removal. Available options are Select date and Duration until removal (in hours)
      • Select date: Click the calendar to select the specific date for removal.
      • Duration until removal (in hours): Type a number, in hours, until policy removal occurs.
    • Allow user to remove policy: You can select when users can remove the policy from their device. Select Always, Passcode required, or Never from the menu. If you select Passcode required, type a passcode in the Removal passcode field.
    • Profile scope: Select whether this policy applies to a User or an entire System. The default is User. This option is available only on macOS 10.7 and later.

Android settings

Credentials policy configuration screen

Configure the following settings:

  • Credential type: In the list, click the type of credential to use with this policy, and then enter the following information for the selected credential:
    • Certificate
      • Credential name: Type a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and then navigating to the file’s location.
    • Keystore
      • Credential name: Type a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and then navigating to the file location.
      • Password: Type the keystore password for the credential.
    • Server certificate
      • Server certificate: In the list, click the certificate to use.
    • Credential provider
      • Credential provider: In the list, click the name of the credential provider.

Android Enterprise settings

Credentials policy configuration screen

Configure these settings to determine how credentials settings are applied:

  • Remove credentials: Set to On to configure the following settings. Default is Off.
    • Remove user credentials: Removes certificates from the managed keystore. Default is Off.
    • Remove trusted root certificates: Uninstalls all non-system CA certificates. Default is Off.
  • Apply to fully managed devices with a work profile/Work profile on corporate-owned devices: Allows you to configure credentials policy settings for fully managed devices with work profiles. When this setting is On, select one of these settings. This policy applies to the work profile on devices only.

Configure the credential settings:

  • Credential type: In the list, click the type of credential to use with this policy, and then enter the following information for the selected credential:
    • Certificate
      • Credential name: Type a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and then navigating to the file location.
    • Keystore
      • Credential name: Type a unique name for the credential.
      • The credential file path: Select the credential file by clicking Browse and then navigating to the file location.
      • Password: Type the keystore password for the credential.
      • Certificate Alias: A certificate alias makes it easier for apps to access the certificate. Configure a certificate alias in the Android Enterprise Managed Configuration device policy. Then, type the alias in the Certificate Alias field in the Credentials device policy. Apps retrieve the certificate and authenticate the VPN without any action by users.
    • Server certificate
      • Server certificate: In the list, click the certificate to use.
    • Credential provider
      • Credential provider: In the list, click the name of the credential provider.
      • Apps to use certificates: To specify apps that have silent access to the credentials from this provider: Click Add, select an app, and click Save.
      • Certificate Alias: A certificate alias makes it easier for apps to access the certificate. Configure a certificate alias in the Android Enterprise Managed Configuration device policy. Then, type the alias in the Certificate Alias field in the Credentials device policy. Apps retrieve the certificate and authenticate the VPN without any action by users.

Chrome OS settings

In this preview, Chromebook devices can use the credential policy to take advantage of the Chrome operating system’s built-in certificate management. Administrators can upload a certificate authority’s private certificate for signing and issuing the client certificates. This certificate allows Citrix Endpoint Management to create and push certificates to Chromebook devices. Device Policies configuration screen

  • Credential type: In the list, click the type of credential to use with this policy and then enter the following information for the selected credential:
    • Keystore
      • The credential file path: Select the credential file by clicking Browse and navigating to the file’s location
      • Password: Enter the keystore password for the credential.

Windows Desktop/Tablet settings

Device Policies configuration screen

  • Certificate Type: In the list, click either ROOT or CLIENT.
  • If you click ROOT, configure these settings:
    • Store device: In the list, click root, My, or CA for the location of the certificate store for the credential. My stores the certificate in users’ certificate stores.
    • Location: For Windows 10 and Windows 11 tablets, System is the only location.
    • Credential type: For Windows 10 and Windows 11 tablets, Certificate is the only credential type.
    • Credential file path: Select the certificate file by clicking Browse and navigating to the file’s location.
  • If you click CLIENT, configure these settings:
  • Location: For Windows 10 and Windows 11 tablets, System is the only location.
  • Credential type: For Windows 10 and Windows 11 tablets, Keystore is the only credential type.
  • Credential name: Type the name of the credential. This field is required.
  • Credential file path: Select the certificate file by clicking Browse and navigating to the file’s location.
  • Password: Type the password associated with the credential. This field is required.

Workspace Hub settings

Device Policies configuration screen

  • The credential file path: Browse for the CA certificate file or .zip file containing the certificates to upload. This policy supports .cer, .crt, .pem, and .der certificate files.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据

词条统计

浏览:14 次

字数:15139

最后编辑:7年前

编辑次数:0 次

    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文