Choose your language

Choose your login

Support

How can we help?

PaperCut's AI-generated content is continually improving, but it may still contain errors. Please verify as needed.

Lightbulb icon
Lightbulb icon

Here’s your answer

Sources:

* PaperCut is constantly working to improve the accuracy and quality of our AI-generated content. However, there may still be errors or inaccuracies, we appreciate your understanding and encourage verification when needed.

Lightbulb icon

Oops!

We currently don’t have an answer for this and our teams are working on resolving the issue. If you still need help,
User reading a resource

Popular resources

Conversation bubbles

Contact us

Enabling client certificates for the Mobility Print Android app via Google Workspace

This page applies to:

Some customer sites might be configured so end-user devices (clients) in the corporate network require client certificates to authenticate to internal resources.

This usually involves provisioning the clients with organization-approved digital certificates, and setting up a proxy between clients and various central resources the clients need to access (for example, in this case, the Mobility Print server).

Some other examples of resources that clients must have a certificate to access include:

  • a corporate network via VPN
  • internal web applications.

For these sites, you can configure the certificate alias via Google Workspace so that the Mobility Print Android app can retrieve the provisioned certificates from the device keychain and use them in network requests to the Mobility Print server.

Before you start

Confirm the following before configuring the client certificate alias in Google Workspace:

  • Ensure you have in place a properly configured environment with client certificate validation and provision on end-user devices.
  • Grant KeyPair access permission for the correct client certificate to the Mobility Print Android app (Package name: com.papercut.projectbanksia) on the devices. This access is required for the app to access client certificates from the device KeyChain or to use in network requests.
  • This feature works only in a managed setting. If you want to set up this functionality you must be already using device management for Android (for example, via Google Workspace).

Steps

  1. Specify the certificate alias in the device configuration profile in Google Workspace. Do this through Apps > Web & mobile apps > Mobility Print > Settings > Add configuration (under the Managed configuration section).

    Settings section
    Add configuration section

  2. Add a new config profile with the client certificate alias specified.
    Create new config profile

  3. Click Save.

Handy tips for managing client certificates via Google Workspace

  • Communicate with users that they need to select their work profile on their Android devices because their private profile won’t be able to connect using client certificates.
  • Don’t force install through Google Workspace. This is because users won’t be prompted to set notification permissions, and therefore may not be prompted to authenticate. Instead, configure the app in Google Workspace with the ‘Optional install’ option turned on.

 

….. We’d like to hear from you in the Comments section below any further tips you might have to help manage client certificates.

 

Comments