To provide single sign-on to the users' app portal and resources from devices managed by AirWatch, in the VMware Identity Manager admin console enable and configure the Mobile SSO for iOS authentication method in the built-in identity provider in Identity Manager. The built-in identity provider manages the KDC service. When users sign in from their iOS devices, the Mobile SSO for iOS authentication method in the built-in identity provider is used to authenticate users.

Certificate authority PEM or DER file used to issue certificates to users in the AirWatch tenant.

For revocation checking, the OCSP responder's signing certificate.


In the administration console, Identity & Access Management tab, select Manage > Identity Providers.


Click the identity provider labeled Built-in and configure the identity provider details.


In the Authentication Methods section, click the Mobile SSO (for iOS) gear icon.


In the KdcKerberosAuthAdapter page configure Kerberos authentication method.



Enable KDC

Select this check box to enable users to sign in using iOS devices that support Kerberos authentication.

Root and Intermediate CA Certificate

Upload the certificate authority issuer certificate file. The file format can be either PEM or DER.

Uploaded CA Certificate Subject DNs

The contents of the uploaded certificate file is displayed here. More than one file can be uploaded and whatever certificates that are included are added to the list.

Enable OCSP

Select the check box to use the Online Certificate Status Protocol (OCSP) certificate validation protocol to get the revocation status of a certificate.

Send OCSP Nonce

Select this check box if you want the unique identifier of the OCSP request to be sent in the response.

OCSP Responder’s Signing Certificate

Upload the OCSP certificate for the responder.

When you are using the AirWatch Certificate Authority, the issuer certificate is used as the OCSP certificate. Upload the AirWatch certificate here as well.

OCSP Responder’s Signing Certificate Subject DN

The uploaded OCSP certificate file is listed here.

Enable Cancel Link

When authentication is taking too long, give the user the ability to click Cancel to stop the authentication attempt and cancel the sign-in.

When the Cancel link is enabled, Cancel appears at the end of the authentication error message that displays.

Cancel Message

Create a custom message that displays when the Kerberos authentication is taking too long. If you do not create a custom message, the default message is Attempting to authenticate your credentials.


Click Save.


In the Built-in Identity Provider page, KDC Certificate Export section, click Download Certificate.

Save this certificate to a file that can be access from the AirWatch admin console. You upload this certificate when you configure the iOS device profile in AirWatch.


Click Save on the built-in identity provider page.

Configure the default policy rule for Kerberos authentication for iOS devices. Make sure that this authentication method is the first method set up in the rule.

Go to the AirWatch admin console and configure the iOS device profile in AirWatch and add the KDC server certificate issuer certificate from Identity Manager.