Integration with ManageEngine Mobile Device Manager Plus (MDM)
Overview
Key Manager Plus integrates with ManageEngine Mobile Device Manager Plus (MDM); this integration is achieved through the ManageEngine MDM APIs. Once the integration is done, you can discover and import SSL certificates from the devices managed through your MDM server and store the SSL certificates in the Key Manager Plus repository. You can also deploy SSL certificates from Key Manager Plus to the mobile devices listed in your MDM environment. All the imported SSL certificates are stored in the Key Manager Plus repository, from where you can filter the view based on the OS type such as iOS, Android, Windows, Chrome OS, Mac OS, and Apple tvOS. In addition to that, Key Manager Plus allows you to export instant and periodically scheduled reports of the MDM certificates that are managed in the certificate repository within a selected time period.
Note: The Key Manager Plus - ManageEngine MDM integration works with MDM release version 10.1.2011.02 and above only.
1. Prerequisite
The Key Manager Plus - ManageEngine MDM integration requires a valid API key with the necessary permissions. To generate the API server key, follow the below steps in the ManageEngine MDM portal:
- Navigate to Admin and click Generate Key under API Key Generation.
- In the pop-up, choose Third-party App as the Application, enter a Service Name, and under Permissions, select the following: CertMgmt (read and write), Devices (read and write), Profiles (read and write).
- Click Generate Key. Once the new API key is generated, use the copy icon to copy it. This key is necessary to perform certificate discovery in the following discovery steps.
2. Discover SSL Certificates from ManageEngine MDM
Once you have the API server key from the MDM portal, follow the below steps in the Key Manager Plus interface to discover SSL certificates from the devices managed in MDM:
- Navigate to Discovery >> ManageEngine MDM.
- Specify the URL of the ManageEngine MDM server and enter the newly generated API Key.
- Click Import. Key Manager Plus will establish a secure connection with the MDM server and start importing SSL certificates into the repository.
- Click Discovery Audit to view the status of the import.
Alternatively, you can also discover and import certificates through the Manage option from the Integrations >> Others >> MDM page. This is explained in detail under the subsequent steps.
3. Import and Deploy SSL Certificates
All the SSL certificates discovered from the MDM server are stored in the certificate repository and you can access them from the Integrations >> Others >> ManageEngine MDM. The ManageEngine MDM tab displays certificate attributes such as the Common Name, Device Name, Issuer, Date of Expiry, Signature Algorithm, and Serial Number. Using the Show drop-down, you can filter the view of the SSL certificates based on the following OS types: iOS, Android, Windows, Chrome OS, Mac OS, and Apple tvOS.
From the ManageEngine MDM tab, you can import, deploy, and manage the SSL certificates discovered from the MDM portal.
3.1 Import SSL Certificates
Follow the below steps to import certificates from the MDM server:
- If you have not previously discovered certificates through the Discovery tab, navigate to Integrations >> Others >> MDM and click Manage.
- In the pop-up that appears, enter the server URL, API server key, and click Save.
- Click Import option on the MDM Certificates window to fetch certificates from the devices in your MDM server.
However, if you have already discovered certificates via the Discovery tab, you can skip this step as your certificates will already be available in Key Manager Plus.
3.2 Deploy SSL Certificates
Key Manager Plus allows you to deploy SSL certificates to the various devices in your MDM server. Follow the below steps:
- Navigate to Integrations >> Others >> MDM.
- Select one or more certificates from the certificates list and click Deploy.
- In the pop-up that appears, choose a Device Platform, select the required devices from the list of devices associated with your MDM server. Use the checkboxes and select Certificate and/or JKS/PKCS based on your requirement. Click Deploy.
- To get the deployment status, go to Deploy Audit and click the Get Status option.
Note that the deployment status will not be updated instantly, as ManageEngine MDM puts deployment requests on a queue until the selected device is online. Click the Get Status option whenever you need to get the updated deployment status.
3.3 Show and Delete Certificates
- You can filter the certificates view using the Show option. Click the Show drop-down and choose the required OS types from the list. The certificates in the table view will be filtered as per your selection.
- To delete certificates from the table view, select the required certificates using the checkboxes and click Delete from the menu. Click Confirm in the confirmation dialog box.
4. Create MDM Certificates Report
Key Manager Plus offers a provision to export reports of the MDM certificates managed in the Key Manager Plus repository within a selected period. This report provides detailed information on the MDM certificates managed via Key Manager Plus. Additionally, you can schedule periodic generation of MDM certificate reports.
Follow the below steps to create the MDM Certificates Report:
- Navigate to the Reports tab and click MDM Certificates Report under SSL Reports.
- This report includes details such as: Common Name, Device Name, Issuer, Date of Expiry, Signature Algorithm, and Serial Number.
- Click the Show drop-down to filter the report view based on the OS type.
- Click the Date Filter and choose a time period to view certificates imported within the specified dates.
- Click the Export drop-down to export this report in PDF & CSV formats, or send via email to the specified recipients.
Click here to learn more about Reports in Key Manager Plus.
Follow the below steps to schedule periodic generation of the MDM certificates report:
- Go to the Schedule tab.
- Add a Schedule Name and choose the Schedule Type as Report.
- Under Report Type, choose MDM Certificates Report.
- Enter a preferred recurrence type, date and time.
- Choose a report format and click Save.
Once the schedule is created, Key Manager Plus will periodically generate the MDM Certificates Report on the specified date and time.
Click here to learn more about Schedules in Key Manager Plus.