In Entrust Certificate Authority, create a client policy and a role to allow PKCS #12 enrollment through the MDMWS protocol.

Creating a client policy for MDMWS P12 enrollment

See below to create an Entrust Certificate Authority client policy for MDMWS P12 enrollment.

To create a client policy for MDMWS P12 enrollment

  1. Log in to Entrust Certificate Authority Administration.
  2. In the tree view, select Security Policy > User Policies > End User Policy.
  3. Select User Policies > Selected User Policy > Copy. The Copy User Policy dialog box appears.
  4. In the Label field, enter End User P12 Policy.
  5. In the Common name field, enter End User P12 Policy.
  6. Under Policy Attributes:
    • Select Allow PKCS#12 Export.
    • Deselect All exportable.
  7. Click Apply.
  8. If prompted, authorize the operation.

Creating a role for MDMWS P12 enrollment

See below to create an Entrust Certificate Authority role allowing PKCS #12 export.

In CA Gateway, the CA profile Certificate Enrollment Gateway will use for MDMWS enrollment must assign this role to end users. The XAP administrator profile used to manage the CA profile must also have permission to administer this role.

To create a role for MDMWS P12 enrollment

  1. Log in to Entrust Certificate Authority Administration.
  2. In the tree view, select Security Policy > Roles > End User.
  3. Select User Policies > Selected Role > Copy. A copy of the role appears at the bottom of the list of roles in the tree view, and the new role’s properties appear in the right pane.
  4. In the Unique name field, enter End User P12.
  5. In the User Policy drop-down list, select End User P12 Policy.
  6. Click Apply.
  7. If prompted, authorize the operation.