Deploy a cert

%3CLINGO-SUB%20id%3D%22lingo-sub-1498463%22%20slang%3D%22en-US%22%3EDeploy%20a%20cert%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1498463%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20community%20members%2C%3C%2FP%3E%3CP%3EWe%20are%20using%20Intune%20to%20deliver%20a%20couple%20of%20certs%20to%20the%20mobile%20devices.%20We%20did%20both%20Root%20and%20Intermediate%20certs%20using%20Device%20Configuration%20Profile%20with%20Trusted%20Cert%20option%2C%20which%20worked%20on%20both%20iOS%20and%20Android.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20it%20comes%20to%20an%20application%20cert%2C%20with%20.cer%20extension.%20It%20is%20a%20certificate%20that%20required%20by%20an%20app%20on%20the%20mobiles%20(which%20is%20also%20published%20by%20Intune)%20that%20uses%20to%20authenticate%20with%20its%20cloud%20service.%20We%20need%20to%20get%20this%20certificate%20on%20to%20the%20mobile%20phones.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20certificate%20name%20started%20with%20a%20wildcard%20*.xxx.mycompanydomain%2C%20with%20multiple%20URLs%20inside%20the%20cert.%20At%20first%2C%20we%20didn't%20know%20which%20options%20should%20be%20used%2C%20whether%20it%20is%20Trusted%20Cert%2C%20PKCS%2C%20Imported%20PKCS%2C%20SCEP%2C%20etc.%20So%20we%20started%20to%20deploy%20this%20app%20cert%20using%20Trusted%20Certificate%20option.%20The%20certificate%20installed%20on%20the%20iOS%20but%20it%20didn't%20install%20on%20the%20Android.%20And%20we%20tried%20both%20Android%20Enterprise%20with%20Work%20Profile%20and%20the%20fully%20managed%20Android%2C%20neither%20worked.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20we%20looked%20at%20the%20other%20cert%20option%2C%20such%20as%20PKCS%20and%20SCEP.%20They%20require%20complex%20infrastructure%20set%20up%20and%20doesn't%20look%20like%20it's%20the%20right%20option%20to%20go%2C%20given%20we%20only%20deploying%20this%20static%20app%20cert%2C%20which%20is%20same%20for%20every%20single%20device.%20It%20feels%20like%20the%20same%20deal%20as%20the%20root%20cert%2C%26nbsp%3Bjust%20need%20to%20be%20present%20on%20the%20mobiles.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20anyone%20have%20similar%20experience%3F%20Is%20there%20anything%20we%20are%20doing%20wrong%20deploying%20the%20cert%20to%20the%20Android%20device%3F%20Does%20the%20name%20of%20the%20cert%20that%20started%20with%20a%20Wildcard%20matters%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20all.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1498463%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ecert%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ecertificate%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1501720%22%20slang%3D%22en-US%22%3ERe%3A%20Deploy%20a%20cert%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1501720%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F624018%22%20target%3D%22_blank%22%3E%40wangjueliang%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Etrusted%20certificate%20should%20be%20fine%20in%20your%20case%2C%20that's%20the%20correct%20way%20of%20distributing%20such%20a%20certificate.%20In%20the%20case%20of%20Android%20did%20you%20check%20with%26nbsp%3B%3CA%20class%3D%22link-a079aa82--primary-53a25e66--link-faf6c434%22%20href%3D%22https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.wesbunton.projects.mycertificates%26amp%3Bhl%3Den%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20nofollow%22%20data-key%3D%22b4e798c3f66047e180dc7140c20c8803%22%3E%3CSPAN%20data-key%3D%224bdf99421eb94230ad964173b621616b%22%3EMy%20Certificates%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-key%3D%22fa77621c885746869f0fba17e3091de0%22%20data-slate-fragment%3D%22JTdCJTIyb2JqZWN0JTIyJTNBJTIyZG9jdW1lbnQlMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMlRvJTIwY2hlY2slMjBpZiUyMHlvdXIlMjBjZXJ0aWZpY2F0ZSUyMHJ1bnMlMjB3ZWxsJTIwb24lMjB5b3VyJTIwQW5kcm9pZCUyMGRldmljZSUyMHlvdSUyMGNhbiUyMHVzZSUyMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTJDJTdCJTIyb2JqZWN0JTIyJTNBJTIyaW5saW5lJTIyJTJDJTIydHlwZSUyMiUzQSUyMmxpbmslMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlMjJocmVmJTIyJTNBJTIyaHR0cHMlM0ElMkYlMkZwbGF5Lmdvb2dsZS5jb20lMkZzdG9yZSUyRmFwcHMlMkZkZXRhaWxzJTNGaWQlM0Rjb20ud2VzYnVudG9uLnByb2plY3RzLm15Y2VydGlmaWNhdGVzJTI2aGwlM0RlbiUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIyb2JqZWN0JTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyTXklMjBDZXJ0aWZpY2F0ZXMlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiUyMGZyb20lMjBHb29nbGUlMjBQbGF5LiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE%22%3E%20from%20Google%20Play%20Store%3F%20I%20often%20had%20the%20case%20that%20the%20certificate%20was%20simply%20not%20shown%20and%20the%20app%20mentioned%20above%20revealed%20it%20as%20deployed%20and%20available.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-key%3D%22fa77621c885746869f0fba17e3091de0%22%20data-slate-fragment%3D%22JTdCJTIyb2JqZWN0JTIyJTNBJTIyZG9jdW1lbnQlMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMlRvJTIwY2hlY2slMjBpZiUyMHlvdXIlMjBjZXJ0aWZpY2F0ZSUyMHJ1bnMlMjB3ZWxsJTIwb24lMjB5b3VyJTIwQW5kcm9pZCUyMGRldmljZSUyMHlvdSUyMGNhbiUyMHVzZSUyMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTJDJTdCJTIyb2JqZWN0JTIyJTNBJTIyaW5saW5lJTIyJTJDJTIydHlwZSUyMiUzQSUyMmxpbmslMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlMjJocmVmJTIyJTNBJTIyaHR0cHMlM0ElMkYlMkZwbGF5Lmdvb2dsZS5jb20lMkZzdG9yZSUyRmFwcHMlMkZkZXRhaWxzJTNGaWQlM0Rjb20ud2VzYnVudG9uLnByb2plY3RzLm15Y2VydGlmaWNhdGVzJTI2aGwlM0RlbiUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIyb2JqZWN0JTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyTXklMjBDZXJ0aWZpY2F0ZXMlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiUyMGZyb20lMjBHb29nbGUlMjBQbGF5LiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE%22%3Ebest%2C%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-key%3D%22fa77621c885746869f0fba17e3091de0%22%20data-slate-fragment%3D%22JTdCJTIyb2JqZWN0JTIyJTNBJTIyZG9jdW1lbnQlMjIlMkMlMjJkYXRhJTIyJTNBJTdCJTdEJTJDJTIybm9kZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJibG9jayUyMiUyQyUyMnR5cGUlMjIlM0ElMjJwYXJhZ3JhcGglMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlN0QlMkMlMjJub2RlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMlRvJTIwY2hlY2slMjBpZiUyMHlvdXIlMjBjZXJ0aWZpY2F0ZSUyMHJ1bnMlMjB3ZWxsJTIwb24lMjB5b3VyJTIwQW5kcm9pZCUyMGRldmljZSUyMHlvdSUyMGNhbiUyMHVzZSUyMCUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTJDJTdCJTIyb2JqZWN0JTIyJTNBJTIyaW5saW5lJTIyJTJDJTIydHlwZSUyMiUzQSUyMmxpbmslMjIlMkMlMjJpc1ZvaWQlMjIlM0FmYWxzZSUyQyUyMmRhdGElMjIlM0ElN0IlMjJocmVmJTIyJTNBJTIyaHR0cHMlM0ElMkYlMkZwbGF5Lmdvb2dsZS5jb20lMkZzdG9yZSUyRmFwcHMlMkZkZXRhaWxzJTNGaWQlM0Rjb20ud2VzYnVudG9uLnByb2plY3RzLm15Y2VydGlmaWNhdGVzJTI2aGwlM0RlbiUyMiU3RCUyQyUyMm5vZGVzJTIyJTNBJTVCJTdCJTIyb2JqZWN0JTIyJTNBJTIydGV4dCUyMiUyQyUyMmxlYXZlcyUyMiUzQSU1QiU3QiUyMm9iamVjdCUyMiUzQSUyMmxlYWYlMjIlMkMlMjJ0ZXh0JTIyJTNBJTIyTXklMjBDZXJ0aWZpY2F0ZXMlMjIlMkMlMjJtYXJrcyUyMiUzQSU1QiU1RCU3RCU1RCU3RCU1RCU3RCUyQyU3QiUyMm9iamVjdCUyMiUzQSUyMnRleHQlMjIlMkMlMjJsZWF2ZXMlMjIlM0ElNUIlN0IlMjJvYmplY3QlMjIlM0ElMjJsZWFmJTIyJTJDJTIydGV4dCUyMiUzQSUyMiUyMGZyb20lMjBHb29nbGUlMjBQbGF5LiUyMiUyQyUyMm1hcmtzJTIyJTNBJTVCJTVEJTdEJTVEJTdEJTVEJTdEJTVEJTdE%22%3EOliver%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Dear community members,

We are using Intune to deliver a couple of certs to the mobile devices. We did both Root and Intermediate certs using Device Configuration Profile with Trusted Cert option, which worked on both iOS and Android. 

 

Then it comes to an application cert, with .cer extension. It is a certificate that required by an app on the mobiles (which is also published by Intune) that uses to authenticate with its cloud service. We need to get this certificate on to the mobile phones.

 

The certificate name started with a wildcard *.xxx.mycompanydomain, with multiple URLs inside the cert. At first, we didn't know which options should be used, whether it is Trusted Cert, PKCS, Imported PKCS, SCEP, etc. So we started to deploy this app cert using Trusted Certificate option. The certificate installed on the iOS but it didn't install on the Android. And we tried both Android Enterprise with Work Profile and the fully managed Android, neither worked.

 

Then we looked at the other cert option, such as PKCS and SCEP. They require complex infrastructure set up and doesn't look like it's the right option to go, given we only deploying this static app cert, which is same for every single device. It feels like the same deal as the root cert, just need to be present on the mobiles.

 

Does anyone have similar experience? Is there anything we are doing wrong deploying the cert to the Android device? Does the name of the cert that started with a Wildcard matters?

 

Thanks all.

1 Reply

Hey @wangjueliang,

 

trusted certificate should be fine in your case, that's the correct way of distributing such a certificate. In the case of Android did you check with My Certificates from Google Play Store? I often had the case that the certificate was simply not shown and the app mentioned above revealed it as deployed and available.

 

best,

Oliver