Samsung Knox 编辑
Samsung offers several solutions that are compatible with XenMobile Server.
- XenMobile supports and extends Samsung Knox policies on compatible Samsung devices.
- The Knox Service plug-in (KSP) is an app that supports a subset of Knox Platform for Enterprise (KPE) features. For information from Samsung about KPE, see Configure Knox Platform for Enterprise and Overview.
You can configure XenMobile to query the Samsung Knox attestation server REST APIs.
Samsung Knox uses hardware security capabilities that provide multiple levels of protection for the operating system and applications. One level of this security resides at the platform through attestation. An attestation server provides verification of the mobile device core system software (for example, the boot loaders and kernel). The verification occurs at runtime based on data collected during trusted boot.
In the XenMobile web console, click the gear icon in the upper-right corner. The Settings page appears.
Under Platforms, click Samsung KNOX. The Samsung KNOX page appears.
In Enable Samsung KNOX attestation, select whether to enable Samsung Knox attestation. The default is NO.
When you set Enable Samsung KNOX attestation, to YES, the Web service URL option is enabled. Then, in the list, do one of the following:
Click the appropriate attestation server.
Click Add new and then enter the Web service URL.
Click Test Connection to verify the connection. A success or failure message appears.
Click Save.
Note:
You can use Samsung Knox Mobile Enrollment to enroll multiple Samsung Knox devices into XenMobile (or any mobile device manager) without manually configuring each device. For information, see Samsung Knox bulk enrollment.
Add the Knox service plug-in app
If you plan on using Android Enterprise with Knox, add the Knox service plug-in (KSP) to XenMobile. The KSP app uses AndroidOEMConfig to support features such as security policies, flexible VPN configuration, and biometric authentication controls. AndroidOEMConfig enables OEMs and endpoint mobility managers (EMM) to support custom OEM APIs. Those APIs cover use cases not supported through Android Enterprise.
For more information on KSP, see the Knox Service Plugin Guide.
- Sign in to your Google account and navigate to
https://play.google.com/work/apps/details?id=com.samsung.android.knox.kpu
. Approve the Knox Service Plug-in app. - Sign in to your XenMobile console and add the Knox service plug-in as a public app store app. For more information on adding public app store apps, see Add a public app store app.
- In your XenMobile console, navigate to Configure > Device policies. Click Add.
- Click Managed Configurations. In the dialog that comes up, select Knox Service Plugin from the menu. For more information on the Managed configuration policy, see Managed configurations policy.
- Type a name for the policy then continue to the platform page.
- On the platform page, type a Profile name for your Knox profile and input the KPE Premium License key from Samsung. The policies that appear below these fields come from your Knox deployment. For more information on Knox policies, see the Knox Service Admin Plug-in Guide referenced earlier in this section.
- Click Next and configure deployment rules for the policy.
- Click Save.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论