Certificate

This configuration installs a CA certificate or a certificate with private key on the device.

The Certificate configuration distributes a certificate from the Relution certificate management, a certificate issued via a certificate template, or the user certificate of the assigned user to Android Enterprise devices. A policy can contain several certificate configurations.

The installation is carried out by the Relution Companion app, which Relution grants permission to install certificates (see Companion & Daemon →).


General

The General area defines which certificate is installed.

  • Selected certificate or template (preselected) – in the Certificate or certificate template field, Select opens the Select a certificate or a certificate template dialog. There, an uploaded certificate is available on the Certificates tab and a certificate template on the Certificate templates tab. Certificates in PKCS#1 and PKCS#12 format are offered. Without a selection, the configuration cannot be saved.
  • User’s certificate for VPN and apps – instead of a fixed certificate, the certificate stored under VPN and apps in the profile of the user assigned to the device is installed.
    • Certificate name – selects a specific certificate by name when the user has several certificates of this type. The field may contain placeholders resolved per device (see Advanced placeholders →). If left blank, the longest-lived certificate is used.

Certificates in PKCS#1 format are installed as CA certificates, PKCS#12 containers as certificates with private key.

Background on the certificate sources:


Certificate alias

The alias is generated automatically as soon as a certificate, a template or the option User’s certificate for VPN and apps is selected, and cannot be edited. The copy icon copies it to the clipboard.

The portal describes its purpose as follows: when a managed configuration requires a certificate alias, this value is used to refer to this configuration.

To keep the alias unique on the device, Relution passes it to the Companion app extended by the hexadecimal serial number of the certificate in parentheses.


Behavior when a user certificate is missing

If the user assigned to the device has no matching user certificate, Relution still transfers the other configurations of the policy. The certificate is then not installed, and a warning is written to the server log.

Top