background image

Configure the BlackBerry MDS Connection Service to authenticate on behalf of
BlackBerry devices with the RSA Authentication Manager

When you turn on RSA® authentication, users must type their login credentials on their BlackBerry® devices before they can
access intranet or Internet content. After the user is authenticated, if proxy authentication is configured, the BlackBerry
device prompts the user to authenticate with the proxy server. By default, the BlackBerry device is authenticated for 24
hours, and an inactive BlackBerry device remains connected for 60 minutes.
1.

In the BlackBerry Manager, click the Connection Service tab.

2.

Click Edit Connection Service Properties.

3.

In the left pane, click RSA Authentication.

4.

Click Enable RSA Authorization Support.

5.

In the drop-down list, click True.

6.

To specify the length of time that an authenticated BlackBerry device can remain connected to your organization's
network before the user must log in again, double-click RSA Authentication Timeout.

7.

Type a value, in minutes.

8.

To specify the length of time that an inactive BlackBerry device can remain connected to your organization's network
before the user must log in again, double-click RSA Inactivity Timeout.

9.

Type a value, in minutes.

10. Click Apply.

Allowing push applications on external web servers to make trusted
connections to the BlackBerry MDS Connection Service

You can configure the BlackBerry® MDS Connection Service to allow push applications on untrusted web servers to push
content and updates to BlackBerry devices. If you want to establish trusted connections between external web servers and
the BlackBerry MDS Connection Service, you must initialize a key store file (webserver.keystore) on the computer on which
the BlackBerry MDS Connection Service is installed. This allows the BlackBerry MDS Connection Service to accept HTTPS
connections from push applications on external web servers.

Your organization can trust a web server that hosts push applications but is external to your environment if the BlackBerry®
Professional Software stores a certificate for it in the key store file. To trust external web servers, you can configure BlackBerry
devices to use the BlackBerry MDS Connection Service to retrieve certificate information for web servers that host push
applications, and then use the Java® keytool to install the certificates on the computer on which the BlackBerry MDS
Connection Service is installed. Push applications can then use the trusted certificates to authenticate with the BlackBerry
MDS Connection Service.

The BlackBerry MDS Connection Service supports LDAP and OCSP for certificate and certificate status retrieval, and SSL/
TLS for authenticated connections using trusted certificates.

Administration Guide

Allowing push applications on external web servers to make trusted connections to the BlackBerry MDS

Connection Service

53

Summary of Contents for PROFESSIONAL SOFTWARE FOR MICROSOFT EXCHANGE

Page 1: ...Administration Guide BlackBerry Professional Software for Microsoft Exchange Version 4 1 Service Pack 4...

Page 2: ...SWD 313211 0911044452 001...

Page 3: ...ckBerry device 12 Protect a stolen BlackBerry device 12 Prepare an existing BlackBerry device for distribution to a new user 13 3 Configuring organizer data synchronization 15 Customizing address book...

Page 4: ...ess book field from the email application to an address book field on all BlackBerry devices 24 Map user defined address book fields to address book fields on all BlackBerry devices 24 Map an address...

Page 5: ...e the maximum file size for attachments 39 Configure the maximum dimensions of image attachments that can display on BlackBerry devices 39 Change the maximum file size of attachments that users can se...

Page 6: ...vices to connect to untrusted external web servers 54 Configure the BlackBerry MDS Connection Service to retrieve certificates for web servers 54 Configure the BlackBerry MDS Connection Service to ret...

Page 7: ...e files in the shared network folder 69 Add the application files to the shared network folder 70 Indexing applications on a network drive 70 Create a software index for the applications in the shared...

Page 8: ...ss license keys 79 Add a CAL key 79 Copy a CAL key to a text file 79 Remove a CAL key 79 11 Removing the BlackBerry Professional Software from the host server 81 Remove the BlackBerry Professional Sof...

Page 9: ...ard 4 In the user list click the name of the user whose BlackBerry Professional Software user account you want to create 5 Click Select 6 Click OK 7 On the Select IT policy screen specify the IT polic...

Page 10: ...r s mailbox so that you can add the user account again at a later time 1 In the BlackBerry Manager click the Users tab 2 Right click the user account that you want to remove Click Delete User 3 Click...

Page 11: ...eld type the maximum number of email messages to load 7 Click OK Options for assigning a BlackBerry device to a user account When you assign a BlackBerry device to a user account you associate the Bla...

Page 12: ...e without requiring the user to have a wired connection to the network in your organization Thewirelessactivationpasswordisspecifictoauseraccount Youcancustomizethepasswordtypeandlength Thepassword ex...

Page 13: ...erry device During the activation process the BlackBerry Desktop Manager prompts the user to associate the BlackBerry device with the user s account on the messaging server and to generate an encrypti...

Page 14: ...e BlackBerry device by issuing commands to lock the BlackBerry device or to make it unavailable 1 In the BlackBerry Manager click the Users tab 2 Right click a user account 3 Click Set Password and Lo...

Page 15: ...Manager click the Local Ports tab c In the Connection list click a connection d Click Wipe Handheld File System e Click Yes f If prompted type the BlackBerry device password to complete the task g Ass...

Page 16: ...ar the check boxes beside the applications that you want to remove Select the check boxes beside the applications that you want to install h Complete the application loader wizard Administration Guide...

Page 17: ...lobal PIM Sync 4 In the Address Book section in the Synchronization Type drop down list click one of the following synchronization options To synchronize address book data from the BlackBerry Professi...

Page 18: ...To synchronize address book data from the BlackBerry device to the BlackBerry Professional Software and from the BlackBerry Professional Software to the BlackBerry device click Bidirectional 5 Ifyouch...

Page 19: ...n intheConflictResolutiondrop downlist clickoneofthefollowingconflict resolution options To specify that the BlackBerry Professional Software information overrules the BlackBerry device information cl...

Page 20: ...r a specific user account 1 In the BlackBerry Manager click the Users tab 2 Double click the user account 3 In the left pane click PIM Sync 4 In the Tasks section in the Synchronization Enabled drop d...

Page 21: ...pane click PIM Sync 4 In the Memos section in the Synchronization Type drop down list click one of the following synchronization options To synchronize memo data from the BlackBerry Professional Soft...

Page 22: ...down list click one of the following conflict resolution options To specify that the BlackBerry Professional Software information overrules the BlackBerry device information click Server Wins To speci...

Page 23: ...drop down list click False 5 Click Apply Customizing message setting synchronization Customize message setting synchronization for all user accounts 1 In the BlackBerry Manager click the Home tab 2 C...

Page 24: ...ply Turn off message setting synchronization for a specific user account 1 In the BlackBerry Manager click the Users tab 2 Double click the user account 3 In the left pane click PIM Sync 4 In the Mess...

Page 25: ...ry Configuration Database correctly the existing organizer data in the BlackBerry Professional Software might be corrupted YoucandeletetheexistingorganizerdatafromtheBlackBerryProfessionalSoftware Thi...

Page 26: ...Control Customization section click Edit PIM Sync Global Field Mapping 3 In the Desktop Field column click User Defined String 1 4 In the Device Field column in the drop down list click the address bo...

Page 27: ...the BlackBerry Manager click the Users tab 2 Click a user account 3 In the lower pane click Service Control Customization 4 Click Edit PIM Sync Field Mapping 5 In the Desktop Field column click User D...

Page 28: ......

Page 29: ...they understand why some of the email message filter rules that they create might not apply to incoming messages If you change global filters the BlackBerry Professional Software reads and applies th...

Page 30: ...e the email message filters from the least restrictive to the most restrictive 14 Click OK Turn on an email message filter that applies to all user accounts The BlackBerry Professional Software applie...

Page 31: ...select the Level1 Notification check box To forward only the message headers of messages with priority status select both the Header Only and Level1 Notification check boxes 11 Click OK 12 In the Fil...

Page 32: ...erry device You can configure the BlackBerry Professional Software to deliver incoming email messages to a user s BlackBerry device when email message filter rules do not apply 1 In the BlackBerry Man...

Page 33: ...irection Managing wireless message reconciliation Wireless message reconciliation synchronizes message status changes between the BlackBerry device and the email applicationonusers computers TheBlackB...

Page 34: ...a signature to all messages sent from a specific user s BlackBerry device Users can change their message signatures either directly from their BlackBerry devices or by using the BlackBerry Desktop Ma...

Page 35: ...Berry Manager click the Home tab 2 Click Edit Server Properties 3 In the left pane click Messaging 4 In the Messaging Options section perform one of the following actions To specify conflict rules for...

Page 36: ...ing message queue The incoming message queue stores incoming email messages that the BlackBerry Professional Software will process and send to BlackBerry devices Delete messages for a specific user fr...

Page 37: ...users send from their BlackBerry devices use the auto BCC option in the BlackBerry Professional Software to send copies of all messages to a specified recipient The auto BCC option populates the BCC f...

Page 38: ......

Page 39: ...f jpeg jpg png tif tiff wmf Microsoft Excel Versions 97 2000 2003 and XP xls Microsoft PowerPoint Versions 97 2000 2003 and XP pps ppt Microsoft Word Versions 97 2000 2003 and XP doc dot Rich Text For...

Page 40: ...lling the size of attachments that users can receive on their BlackBerry devices By default the BlackBerry Attachment Service in the BlackBerry Professional Software does not limit the file size of an...

Page 41: ...est large or complex documents within the same period of time 0 to 10 minutes while the BlackBerry Attachment Service processes large conversions 1 On the server that hosts the BlackBerry Professional...

Page 42: ...Upload Total Attachment Size field type a value that is between 1 and 5120 and that is greater than the Maximum Upload Attachment Size 6 Click OK Optimize the handling of file attachments Youcanoptim...

Page 43: ...documents that can be located in the document cache as DOM for an individual conversion process In the Document Cache Size docs field type a value between 1 and 128 Configure the number of conversion...

Page 44: ...OK 6 On the server that hosts the BlackBerry Professional Software in the Microsoft Windows Services restart the BlackBerry Attachment Service Administration Guide Optimize the handling of file attach...

Page 45: ...T policy rule Default IT policy Basic password security IT policy Medium password security IT policy Medium password security disallow application download IT policy Advanced securityITpolicy Advanced...

Page 46: ...ion Download False False False True False True Force Lock When Holstered False False True True True True Content Protection Strength Strong Strong Disable USB Mass Storage False False False False True...

Page 47: ...or modifications on BlackBerry devices When the BlackBerry device receives an updated default IT policy or a new IT policy the BlackBerry device and BlackBerry Desktop Software apply the configuratio...

Page 48: ...or its use the user cannot change the value of a corresponding field on the BlackBerry device When you select a predefined permitted value to assign to an IT policy rule you restrict the values that t...

Page 49: ...IT policy on 4 Click New Copy 5 Double click IT Policy Name 6 Type a name for the new IT policy 7 In the left pane click a policy group 8 In the right pane double click the IT policy rule 9 Specify a...

Page 50: ...kBerry Professional Software Do not edit the IT policy definitions file 1 Download the xml file that contains IT policy rule definitions from www blackberry com 2 Unzip the file to a temporary folder...

Page 51: ...lick Resend IT Policy 4 Click OK Resend an IT policy to a BlackBerry device automatically 1 In the BlackBerry Manager click the Home tab 2 Click Edit Server Properties 3 In the left pane click IT Admi...

Page 52: ......

Page 53: ...alf of BlackBerry devices If you configure BlackBerry devices to authenticate directly with content servers users are prompted to provide login credentials every 30 minutes on their authenticated Blac...

Page 54: ...on behalf of BlackBerry devices with content servers that use Kerberos 1 Navigate to drive Program Files Research In Motion BlackBerry Enterprise Server MDS Servers Instance config 2 Configure the krb...

Page 55: ...ons to the BlackBerry MDS Connection Service You can configure the BlackBerry MDS Connection Service to allow push applications on untrusted web servers to push content and updates to BlackBerry devic...

Page 56: ...BlackBerry devices Do not change the default LDAP port parameters unless there is a port conflict with another service on the same computer If you change port or host information you must stop and re...

Page 57: ...oftware key store and permit connections to the trusted web server For more information about using the Java keytool visit java sun com j2se 1 5 0 docs tooldocs windows keytool html 1 Copy the certifi...

Page 58: ...erns that specify web servers You assign these URL patterns to a pull rule that you create You can then specify whether users are permitted or denied access to the specified web servers After you crea...

Page 59: ...URL pattern select the Allow check box 7 Click Apply 8 Next you assign the pull rule to a user Assign a pull rule to a specific user 1 In the BlackBerry Manager click the Home tab 2 Click Edit Global...

Page 60: ...You can configure the BlackBerry MDS Connection Service to prevent users from accessing certain types of media that exceed a maximum file size 1 In the BlackBerry Manager click the Home tab 2 Click E...

Page 61: ...P connection with the BlackBerry device The default interval is 120 000 milliseconds 2 minutes 1 In the BlackBerry Manager click the Connection Service tab 2 Click Edit Connection Service Properties 3...

Page 62: ...so that only certain server side push applications can send push requests to BlackBerry devices you can turn on push authentication to restrict the BlackBerry MDS Connection Service from delivering pu...

Page 63: ...er sidepushapplicationmatches the push principal name and password that you specified for the push initiator 10 Click Apply 11 Next you create a push initiator for each server side push application th...

Page 64: ...ne click Access Control 4 Double click Push Initiator Rules 5 In the left pane click a push rule 6 In the right pane select the push initiators for the applications that you want to assign to the push...

Page 65: ...ify device ports for application reliable push requests Application developers can design custom BlackBerry Java Applications to handle application reliable push requests When a BlackBerry Java Applic...

Page 66: ...r push requests stored in the BlackBerry Configuration Database ConfigurestoragesettingsforpushrequestsstoredintheBlackBerryConfiguration Database You can manage your system resources by configuring s...

Page 67: ...re the maximum number of queued connections that the BlackBerry MDS Connection Service can process The BlackBerry MDS Connection Service queues push connections when the number of connections reaches...

Page 68: ...y MDS Connection Service connects to BlackBerry devices Specify the maximum amount of data that the BlackBerry MDS Connection Service can send to BlackBerry devices 1 In the BlackBerry Manager click t...

Page 69: ...kBerrydeviceswhen the number of persistent socket connections reaches the maximum number that you specify 1 In the BlackBerry Manager click the Connection Service tab 2 Click Edit Connection Service P...

Page 70: ...rvice polls for configuration information YoucanspecifyhowoftentheBlackBerry MDSConnectionServicepollstheBlackBerryConfigurationDatabaseforchanges to the BlackBerry MDS Connection Service administrati...

Page 71: ...applications can be added to certain BlackBerry devices Share the network folder 1 On the server that hosts the BlackBerry Professional Software navigate to the following location drive Program Files...

Page 72: ...are configurations can locate the applications that are available to add to BlackBerry devices When you create a software index the BlackBerry Professional Software creates a specification pkg file an...

Page 73: ...te a software configuration you can define application control policies to specify the resources that applications can access on BlackBerry devices from behind your organization s firewall You can als...

Page 74: ...ion 5 In the Configuration Name field rename the software configuration 6 Change the software configuration properties as necessary 7 Click OK Applying application control policies After you create a...

Page 75: ...on control policy rules that are preconfigured on the BlackBerry device click none 7 Click Apply Assign a software configuration to a user account 1 In the BlackBerry Manager click the Users tab 2 Rig...

Page 76: ...anaging applications on BlackBerry devices Change an application control policy 1 In the BlackBerry Manager click the Software Configurations tab 2 Click Manage Application Policies 3 Click the applic...

Page 77: ...a BlackBerry device If the Disposition is set to Required in the application control policy the application upgrade is also sent over the wireless network 1 In the network drive add or upgrade the app...

Page 78: ......

Page 79: ...iple DES algorithm to encrypt and decrypt all data communication between the BlackBerry Professional Software and all BlackBerry devices provides Triple DES encryption only on BlackBerry devices AES e...

Page 80: ...essional Software was configured to use Triple DES only and you change the encryption type to AES only To make this change you must first change to Triple DES or AES then change to AES only The BlackB...

Page 81: ...click License Management 3 Type the new information for the CAL key 4 Click Add License 5 Click Close Copy a CAL key to a text file 1 In the BlackBerry Manager click the Home tab 2 In the Account sec...

Page 82: ......

Page 83: ...rch In Motion HKEY_LOCAL_MACHINE SYSTEM CurrentControlSet Services BBAttachServer and any keys starting with BES or BlackBerry HKEY_LOCAL_MACHINE SYSTEM ControlSet001 Services BBAttachServer and any k...

Page 84: ......

Page 85: ...eneralizedterms RIMreservestherighttoperiodicallychangeinformation that is contained in this documentation however RIM makes no commitment to provide any such changes updates enhancements or other add...

Page 86: ...L SURVIVE A FUNDAMENTAL BREACH OR BREACHES OR THE FAILURE OF THE ESSENTIAL PURPOSE OF THIS AGREEMENT OR OF ANY REMEDY CONTAINED HEREIN AND B TO RIM AND ITS AFFILIATED COMPANIES THEIR SUCCESSORS ASSIGN...

Page 87: ...to corporate applications This product includes software developed by the Apache Software Foundation www apache org and or licensed pursuant to Apache License Version 2 0 www apache org licenses For...

Reviews: