Overview
This article provides Access Control Admins with an overview of Tenant Certificates, which are Device Certificates provided by HENNGE.
Contents
HENNGE Tenant Certificates are Device Certificates issued by our certificate authority.
They are intended to be distributed and used through third-party MDM services.
The existing Device Certificates use Cybertrust's certificate authority, and their association with device identification information can be confirmed in the Access Control Administration.
In contrast, HENNGE Tenant Certificates are specifically designed for distribution through MDM services. As their purpose is to reduce the burden on end users when installing Device Certificates, owner information and information about installed devices cannot be confirmed in the Access Control service.
Please do not use this feature in environments where Admins do not have a means to strictly manage the devices on which the certificate is installed.
Before use, please be sure to review the following prerequisites and Notes.
Comparison with Existing Functionality(Device Certificates)
| Tenant Certificates | Device Certificates | |
| Association with device information | Not associated with device information and can be installed on any device | Associated one-to-one with the Target device information and can only be installed on a specific device |
| Certificate distribution method | Admins use MDM or similar services to install the same Certificate on Target devices | Users install the Certificate on their own devices |
| Usage method | User ID and Password entry is required | Depending on the Configuration, User ID and Password entry is not required |
| Maintaining authentication using the 「Remember this login」 button | Not available. | Authentication can be maintained when using Personal or Passwordless Device Certificates on the new Login screen |
|
Impact if a device with a distributed Certificate is lost |
All Users are affected, and the Certificate must be revoked, reissued, and redistributed to all devices. | Other Users are not affected, and only the Certificate on the Target device must be revoked. |
| Number of certificates available | No limit on the number of devices to which a single Certificate can be distributed | Certificate Count according to your contract |
| Certificate validity period | 13 months from issuance | 5 years from issuance |
Prerequisites
Preparing an MDM Service
Depending on the specifications of the MDM service, distribution to certain OS may not be possible, or operational restrictions may apply.
Please check with your MDM service provider in advance regarding the OS and versions that can be used for distribution.
Notes When Using HENNGE Tenant Certificates
Before using HENNGE Tenant Certificates, please ensure that you understand the following.
-
Any issues that occur on the MDM service side regarding the distribution and use of HENNGE Tenant Certificates, as well as distribution procedures, are not covered by our Support.
Please contact your MDM service provider. - As part of its customer success activities, HENNGE currently provides, on a voluntary basis, procedures that introduce MDM service specifications and Administration screens published in the Help Center and other resources.
-
The Access Control Administration cannot directly manage device information for distributed Certificates. Therefore, Admins must accurately identify and manage Tenant Certificates distributed to each device through the MDM service.
Additionally, because Tenant Certificates are in p12 file format, they can easily be installed on any device or exported without an installer. Due to this characteristic, the Password required for installation must be strictly managed by the Admin.Please understand that if the Password is shared with a User, the risk increases that not only the User themselves, but also unintended third parties may install the Certificate on inappropriate devices.
-
Some devices, including those running certain OS, cannot receive Tenant Certificates.
Please refer to the following for the supported environments for HENNGE Tenant Certificates.
HENNGE One System Requirements - The [Remember this login] feature cannot be used with Tenant Certificates.
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.