Blackberry PRD-10459-003 Administration Guide - Page 160

Configuring the BlackBerry MDS Connection Service to authenticate devices to the RSA Authentication Manager

Page 160 highlights

Administration Guide Configuring how BlackBerry devices authenticate to content servers Configuring the BlackBerry MDS Connection Service to authenticate devices to the RSA Authentication Manager You can configure the BlackBerry® MDS Connection Service to require that BlackBerry device users pass RSA® authentication when they access the Internet or intranet from BlackBerry devices. You can configure the BlackBerry MDS Connection Service to require that users use RSA authentication in one of the following scenarios: • when users access every web site and intranet site from devices • when users access intranet sites from devices • when users access web addresses or intranet addresses that you specify If you configure the BlackBerry MDS Connection Service to require that users use RSA authentication to access web addresses or intranet addresses that you specify, you can choose to apply this option to specific user accounts or to all user accounts that are associated with a BlackBerry® Enterprise Server instance. After the RSA Authentication Manager authenticates the devices, if you configured proxy authentication, the devices prompt users to authenticate to the proxy server. Prerequisites: Configuring the BlackBerry MDS Connection Service to support RSA authentication when the BlackBerry MDS Connection Service runs on Windows Server 2008 • If required, remove the RSA® Authentication Agent from the computer that hosts the BlackBerry® MDS Connection Service. • If required, in the RSA® Authentication Manager, delete the node secret data for the computer that hosts the BlackBerry MDS Connection Service. • If required, delete the node secret data that is located on the computer that hosts the BlackBerry MDS Connection Service. • Retrieve the RSA Authentication API version 5.0.3.2 from RSA. Configure the BlackBerry MDS Connection Service to support RSA authentication when the BlackBerry MDS Connection Service runs on Windows Server 2008 1. On the computer that hosts the BlackBerry® MDS Connection Service, copy the aceclnt.dll file and sdmsg.dll file from the RSA® Authentication API to one of the following folders: • If you are running a 32-bit version of Windows Server® 2008, the :\WINDOWS\system32 folder • If you are running a 64-bit version of Windows Server 2008, the :\WINDOWS\SysWow64 folder 2. In the RSA® Authentication Manager, create an Agent Host record for the BlackBerry® Enterprise Server. The RSA Authentication Manager generates an sdconf.rec file. 3. On the computer that hosts the BlackBerry MDS Connection Service, copy the sdconf.rec file that the RSA Authentication Manager generates to one of the following folders: • If you are running a 32-bit version of Windows Server 2008, the :\WINDOWS\system32 folder • If you are running a 64-bit version of Windows Server 2008, the :\WINDOWS\SysWow64 folder 4. In the Windows® Services, restart the BlackBerry MDS Connection Service. 158

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

Configuring the BlackBerry MDS Connection Service to authenticate
devices to the RSA Authentication Manager
You can configure the BlackBerry® MDS Connection Service to require that BlackBerry device users pass RSA®
authentication when they access the Internet or intranet from BlackBerry devices. You can configure the BlackBerry
MDS Connection Service to require that users use RSA authentication in one of the following scenarios:
when users access every web site and intranet site from devices
when users access intranet sites from devices
when users access web addresses or intranet addresses that you specify
If you configure the BlackBerry MDS Connection Service to require that users use RSA authentication to access web
addresses or intranet addresses that you specify, you can choose to apply this option to specific user accounts or to
all user accounts that are associated with a BlackBerry® Enterprise Server instance.
After the RSA Authentication Manager authenticates the devices, if you configured proxy authentication, the devices
prompt users to authenticate to the proxy server.
Prerequisites: Configuring the BlackBerry MDS Connection Service to support RSA
authentication when the BlackBerry MDS Connection Service runs on Windows Server
2008
If required, remove the RSA® Authentication Agent from the computer that hosts the BlackBerry® MDS
Connection Service.
If required, in the RSA® Authentication Manager, delete the node secret data for the computer that hosts the
BlackBerry MDS Connection Service.
If required, delete the node secret data that is located on the computer that hosts the BlackBerry MDS
Connection Service.
Retrieve the RSA Authentication API version 5.0.3.2 from RSA.
Configure the BlackBerry MDS Connection Service to support RSA authentication
when the BlackBerry MDS Connection Service runs on Windows Server 2008
1.
On the computer that hosts the BlackBerry® MDS Connection Service, copy the
aceclnt.dll
file and
sdmsg.dll
file
from the RSA® Authentication API to one of the following folders:
If you are running a 32-bit version of Windows Server® 2008, the
<drive>
:\WINDOWS\system32 folder
If you are running a 64-bit version of Windows Server 2008, the
<drive>
:\WINDOWS\SysWow64 folder
2.
In the RSA® Authentication Manager, create an Agent Host record for the BlackBerry® Enterprise Server.
The RSA Authentication Manager generates an
sdconf.rec
file.
3.
On the computer that hosts the BlackBerry MDS Connection Service, copy the
sdconf.rec
file that the RSA
Authentication Manager generates to one of the following folders:
If you are running a 32-bit version of Windows Server 2008, the
<drive>
:\WINDOWS\system32 folder
If you are running a 64-bit version of Windows Server 2008, the
<drive>
:\WINDOWS\SysWow64 folder
4.
In the Windows® Services, restart the BlackBerry MDS Connection Service.
Administration Guide
Configuring how BlackBerry devices authenticate to content servers
158