If you set the minimum key size on the BlackBerry Enterprise Server higher than the minimum key size on the BlackBerry
device, the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its certificate
that is less than the minimum key size on the BlackBerry Enterprise Server.
For example, when a user browses to a secure web site that uses a 512-bit DH key in its certificate, the BlackBerry device
prompts the user to trust the web site. If the user trusts the web site and selects the Don't Ask Again option, the minimum
key size on the BlackBerry device is set to 512 bits. If you set the minimum key size on the BlackBerry Enterprise Server to
2048 bits, the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its
certificate that is less than 2048 bits.
Minimum requirements
•
Java® based BlackBerry device
•
BlackBerry® Device Software version 3.6
•
BlackBerry Enterprise Server version 3.6
•
BlackBerry® Connect™ Transport Stack version 4.0
WTLS Minimum Strong ECC Key Length IT policy rule
Description
This rule specifies the minimum ECC key size (in bits) to use during WTLS connections.
Default setting
The default setting on the BlackBerry® device is 163 bits.
The default setting on the BlackBerry® Enterprise Server is 160 bits.
Usage
If you set the minimum key size on the BlackBerry Enterprise Server higher than the minimum key size on the BlackBerry
device, the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its certificate
that is less than the minimum key size on the BlackBerry Enterprise Server.
For example, when a user browses to a secure web site that uses a 160-bit ECC key in its certificate, the BlackBerry device
prompts the user to trust the web site. If the user trusts the web site and selects the Don't Ask Again option, the minimum
key size on the BlackBerry device is set to 160 bits. If you set the minimum key size on the BlackBerry Enterprise Server to
233 bits, the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its certificate
that is less than 233 bits.
Minimum requirements
•
Java® based BlackBerry device
•
BlackBerry® Device Software version 3.6
•
BlackBerry Enterprise Server version 3.6
•
BlackBerry® Connect™ Transport Stack version 4.0
Policy Reference Guide
WTLS policy group
174