Blackberry 8520 User Guide - Page 258

Smart cards, Reject certificate revocation lists from unverified CRL servers

Page 258 highlights

User Guide Security 3. Click Key Stores. 4. Change the Certificate Status Expires After field. 5. Press the Menu key. 6. Click Save. Your BlackBerry® device downloads a new revocation status automatically when your device uses a key store item with a status that is older than the time limit that you set. Reject certificate revocation lists from unverified CRL servers 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options. 3. Click Key Stores. 4. Change the Accept Unverified CRLs field to No. 5. Press the Menu key. 6. Click Save. Your BlackBerry® device rejects certificate revocation lists from CRL servers that the BlackBerry® MDS Connection Service cannot verify. Smart cards About using a smart card with your device Smart cards store certificates and private keys. You can use a smart card reader to import certificates from a smart card to the key store on your BlackBerry® device, but you cannot import private keys. As a result, private key operations such as signing and decryption use the smart card, and public key operations such as verification and encryption use the public certificates on your device. If you use a smart card certificate to authenticate to your device, after you connect your smart card reader to your device, your device requests authentication from the smart card each time that you unlock your device. If the S/MIME Support Package for BlackBerry® devices is installed on your device, you can use smart card certificates to send S/MIMEprotected messages. About two-factor authentication Two-factor authentication, which requires an item that you have (for example, a smart card) and an item that you know (for example, a pass phrase), is designed to provide additional security for your BlackBerry® device. You can use a smart card for two-factor authentication when you log in to your device, or you can use a software token for two-factor authentication when you log in to a VPN, connect to a Wi-Fi® network, or use your device with RSA® software as a hardware token. If you use two-factor authentication, you must type your pass phrase when you • unlock your device 256

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283

3.
Click
Key Stores
.
4.
Change the
Certificate Status Expires After
field.
5.
Press the
Menu
key.
6.
Click
Save
.
Your BlackBerry® device downloads a new revocation status automatically when your device uses a key store item with a status that is older
than the time limit that you set.
Reject certificate revocation lists from unverified CRL servers
1.
On the Home screen or in a folder, click the
Options
icon.
2.
Click
Security Options
.
3.
Click
Key Stores
.
4.
Change the
Accept Unverified CRLs
field to
No
.
5.
Press the
Menu
key.
6.
Click
Save
.
Your BlackBerry® device rejects certificate revocation lists from CRL servers that the BlackBerry® MDS Connection Service cannot verify.
Smart cards
About using a smart card with your device
Smart cards store certificates and private keys. You can use a smart card reader to import certificates from a smart card to the key store on
your BlackBerry® device, but you cannot import private keys. As a result, private key operations such as signing and decryption use the smart
card, and public key operations such as verification and encryption use the public certificates on your device.
If you use a smart card certificate to authenticate to your device, after you connect your smart card reader to your device, your device requests
authentication from the smart card each time that you unlock your device.
If the S/MIME Support Package for BlackBerry® devices is installed on your device, you can use smart card certificates to send S/MIME-
protected messages.
About two-factor authentication
Two-factor authentication, which requires an item that you have (for example, a smart card) and an item that you know (for example, a pass
phrase), is designed to provide additional security for your BlackBerry® device. You can use a smart card for two-factor authentication when
you log in to your device, or you can use a software token for two-factor authentication when you log in to a VPN, connect to a Wi-Fi® network,
or use your device with RSA® software as a hardware token.
If you use two-factor authentication, you must type your pass phrase when you
unlock your device
User Guide
Security
256