Kaspersky Secure Mobility Management

Creating a certificate of mobile devices

February 26, 2024

ID 89730

Expand all | Collapse all

You can create the following types of certificates on a user's mobile device:

  • Mobile certificates for identifying the mobile device
  • Mail certificates for configuring the corporate mail on the mobile device
  • VPN certificate for configuring access to a virtual private network on the mobile device

To create a certificate of mobile devices:

  1. In the console tree, select the Mobile Device Management → Certificates folder.
  2. In the workspace of the Certificates folder, click the Add certificate button to start the Certificate Installation Wizard.
  3. In the Certificate type window of the Wizard, specify the type of certificate that must be installed on the user's mobile device:
    • Mobile certificate

      This certificate is needed for identifying the mobile device.

    • Mail certificate

      This certificate is needed for configuring the corporate mail on the mobile device.

    • VPN certificate

      This certificate is needed for configuring access to a virtual private network on the mobile device.

  4. In the Selecting device type window of the Wizard, Specify the type of the operating system on the device:
    • iOS MDM device

      Select this option if you want to install a certificate on a mobile device that is connected to the iOS MDM Server by using iOS MDM protocol.

    • KES device managed by Kaspersky Security for Mobile

      Select this option if you want to install a certificate on a KES device. In this case, the certificate will be used for user identification upon every connection to the Administration Server.

    • KES device connected to Administration Server without user certificate authentication

      Select this option if you want to install a certificate on a KES device using no certificate authentication. In this case, at the final step of the wizard, in the User notification method window you must select the user authentication type used at every connection to the Administration Server.

    This window is displayed only if you selected Mail certificate or VPN certificate as the certificate type.

  5. In the User selection window of the Wizard, select users, user groups, or Active Directory user groups for which you want to create the certificate.
  6. In the Certificate source window of the Wizard, select the method by which the certificate is created.
    • To create a certificate automatically by using Administration Server tools, select Issue certificate through Administration Server tools.
    • To assign a previously created certificate to a user, select the Specify certificate file option. Click the Browse button to open the Certificate window and specify the certificate file in it.
  7. In the Certificate publishing settings window of the Wizard, select the Do not notify the user about a new certificate check box if you do not want to notify the user about certificate creation. In this case, the User notification method window will not be displayed.
  8. In the User notification method window of the Wizard, configure the settings of mobile device user notification about certificate creation using a text message or via email.

    This window is not displayed if you selected iOS MDM device as the device type or if you selected the Do not notify the user about a new certificate option.

    1. In the Authentication method field, specify the user authentication type:
      • Credentials (domain or alias)
      • One-time password

      This field is displayed if you selected Mobile certificate in the Certificate type window or if you selected KES device connected to Administration Server without user certificate authentication as the device type.

    2. Select the user notification option:
      • Show authentication password after the wizard finishes
      • Notify user of new certificate
        • By email
        • By SMS
  9. In the Generating the certificate window of the Wizard, click Done to finish the Certificate Installation Wizard.

After the wizard finishes, a certificate is created and added to the list of the user's certificates; in addition, a notification is sent to the user, providing the user with a link for downloading and installing the certificate on the mobile device. You can delete and reissue certificates, as well as view their properties.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.