Blackberry 9500 User Guide - Page 108

WTLS options, Add a trusted content server, Prompt if Client Cert Not Found

Page 108 highlights

User Guide Browser security Specify whether your browser accepts and sends data that is encrypted using only FIPS-approved algorithms. Prompt for Server Trust: Specify whether a prompt appears when your browser tries to connect to an untrusted content server that your device does not have an authentication certificate for. Prompt for Domain Name: Specify whether a prompt appears when your browser tries to connect to a content server and the domain name on the authentication certificate for the content server does not match the web address that the browser is trying to connect to. Prompt for Certificate: Specify whether a prompt appears when your browser tries to connect to a content server. You might want a prompt to appear if your device has more than one certificate that you use to authenticate with content servers. Prompt if Client Cert Not Found: Specify whether a prompt appears when your browser tries to connect to a content server, but your device does not have a certificate that can be used to authenticate with the content server. Default Client Cert: Specify the certificate that your browser uses to authenticate with content servers. WTLS options Encryption Strength: Specify whether your browser only accepts and sends data that is encrypted using 128-bit encryption. To accept and send only data that is encrypted using 128-bit encryption, change this field to Strong Only. To accept and send data that is encrypted using 128bit encryption or 56-bit encryption, change this field to Allow Weak. Prompt for Server Trust: Specify whether a prompt appears when your browser tries to connect to an untrusted content server that your device does not have an authentication certificate for. Add a trusted content server Add content servers to your trusted content server list to accelerate the authentication process when you are authenticating with a content server. 1. In the device options, click Security Options. 2. Click TLS. 3. Press the Menu key. 4. Click Add Host. 5. Perform one of the following actions: • If the TLS Default field is set to Proxy, in the Host Name field, type the web address for the content server. • If the TLS Default field is set to Handheld, in the Host Name field, type the web address for the content server. Set the Certificate field to the client certificate that you want to use to authenticate with the content server. 106

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255

Specify whether your browser accepts and sends data that is encrypted using only FIPS-approved algorithms.
Prompt for Server Trust:
Specify whether a prompt appears when your browser tries to connect to an untrusted content server that your device does not have
an authentication certificate for.
Prompt for Domain Name:
Specify whether a prompt appears when your browser tries to connect to a content server and the domain name on the authentication
certificate for the content server does not match the web address that the browser is trying to connect to.
Prompt for Certificate:
Specify whether a prompt appears when your browser tries to connect to a content server. You might want a prompt to appear if your
device has more than one certificate that you use to authenticate with content servers.
Prompt if Client Cert Not Found:
Specify whether a prompt appears when your browser tries to connect to a content server, but your device does not have a certificate
that can be used to authenticate with the content server.
Default Client Cert:
Specify the certificate that your browser uses to authenticate with content servers.
WTLS options
Encryption Strength:
Specify whether your browser only accepts and sends data that is encrypted using 128-bit encryption. To accept and send only data
that is encrypted using 128-bit encryption, change this field to
Strong Only
. To accept and send data that is encrypted using 128-
bit encryption or 56-bit encryption, change this field to
Allow Weak
.
Prompt for Server Trust:
Specify whether a prompt appears when your browser tries to connect to an untrusted content server that your device does not have
an authentication certificate for.
Add a trusted content server
Add content servers to your trusted content server list to accelerate the authentication process when you are authenticating with a content
server.
1.
In the device options, click
Security Options
.
2.
Click
TLS
.
3.
Press the
Menu
key.
4.
Click
Add Host
.
5.
Perform one of the following actions:
If the
TLS Default
field is set to
Proxy
, in the
Host Name
field, type the web address for the content server.
If the
TLS Default
field is set to
Handheld
, in the
Host Name
field, type the web address for the content server. Set the
Certificate
field to the client certificate that you want to use to authenticate with the content server.
User Guide
Browser security
106