Blackberry PRD-10459-003 Administration Guide - Page 167

Configuring certificate server information for the BlackBerry MDS Connection Service

Page 167 highlights

Administration Guide Configuring a BlackBerry MDS Connection Service to trust web servers 3. Click Edit component. 4. On the TLS tab, in the Name field, type the name of a web server. 5. In the Service URL field, type the regular expression for the web address of the web server. 6. In the Settings section, in the Allow untrusted servers drop-down list, perform one of the following actions: • To permit only trusted TLS connections from the web server, click No. • To permit untrusted TLS connections from the web server, click Yes. 7. Click the Add icon. 8. Repeat steps 4 to 7 for each web server that you want to specify. 9. Click Save all. After you finish: Restart the BlackBerry MDS Connection Service. Related topics Add a retrieved certificate for a web server to the key store, 171 Restarting BlackBerry Enterprise Server components, 327 Configuring certificate server information for the BlackBerry MDS Connection Service The certificate for the BlackBerry® MDS Connection Service permits push applications to make HTTPS connection to the BlackBerry MDS Connection Service. You can configure the BlackBerry MDS Connection Service to search for and retrieve certificates and the status of the certificates that external web servers use to make HTTPS connections. To search for and retrieve certificates from an LDAP server, you can configure the BlackBerry MDS Connection Service to use LDAP or DSML. The BlackBerry MDS Connection Service searches each LDAP server using LDAP or DSML in the order that you specify. If you configure the BlackBerry MDS Connection Service to use both LDAP and DSML to search and retrieve certificates, the BlackBerry MDS Connection Service searches the servers using LDAP and then searches the servers using DSML. After the BlackBerry MDS Connection Service retrieves the certificate, the BlackBerry® Enterprise Server sends the certificate to the BlackBerry device, and the BlackBerry device displays the certificate so that the user can accept it. The BlackBerry MDS Connection Service supports DSML version 2. To search for and retrieve the status of the certificates, you can configure the BlackBerry MDS Connection Service to search the OCSP servers or CRL servers. If you search for the status of the certificates using an OCSP server or a CRL server, which server you choose to search for the status of the certificates first does not matter because each server creates a prioritized list automatically. For more information about certificates, see the BlackBerry Enterprise Solution Security Technical Overview. Configure the LDAP servers that the BlackBerry MDS Connection Service uses to retrieve certificates You can create a user name and password so that the BlackBerry® MDS Connection Service can authenticate to LDAP servers on behalf of BlackBerry devices. 165

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

3.
Click
Edit component
.
4.
On the
TLS
tab, in the
Name
field, type the name of a web server.
5.
In the
Service URL
field, type the regular expression for the web address of the web server.
6.
In the
Settings
section, in the
Allow untrusted servers
drop-down list, perform one of the following actions:
To permit only trusted TLS connections from the web server, click
No
.
To permit untrusted TLS connections from the web server, click
Yes
.
7.
Click the
Add
icon.
8.
Repeat steps 4 to 7 for each web server that you want to specify.
9.
Click
Save all
.
After you finish:
Restart the BlackBerry MDS Connection Service.
Related topics
Add a retrieved certificate for a web server to the key store, 171
Restarting BlackBerry Enterprise Server components, 327
Configuring certificate server information for the BlackBerry MDS
Connection Service
The certificate for the BlackBerry® MDS Connection Service permits push applications to make HTTPS connection to
the BlackBerry MDS Connection Service. You can configure the BlackBerry MDS Connection Service to search for and
retrieve certificates and the status of the certificates that external web servers use to make HTTPS connections.
To search for and retrieve certificates from an LDAP server, you can configure the BlackBerry MDS Connection Service
to use LDAP or DSML. The BlackBerry MDS Connection Service searches each LDAP server using LDAP or DSML in the
order that you specify. If you configure the BlackBerry MDS Connection Service to use both LDAP and DSML to search
and retrieve certificates, the BlackBerry MDS Connection Service searches the servers using LDAP and then searches
the servers using DSML. After the BlackBerry MDS Connection Service retrieves the certificate, the BlackBerry®
Enterprise Server sends the certificate to the BlackBerry device, and the BlackBerry device displays the certificate so
that the user can accept it. The BlackBerry MDS Connection Service supports DSML version 2.
To search for and retrieve the status of the certificates, you can configure the BlackBerry MDS Connection Service
to search the OCSP servers or CRL servers. If you search for the status of the certificates using an OCSP server or a
CRL server, which server you choose to search for the status of the certificates first does not matter because each
server creates a prioritized list automatically.
For more information about certificates, see the
BlackBerry Enterprise Solution Security Technical Overview
.
Configure the LDAP servers that the BlackBerry MDS Connection Service uses to
retrieve certificates
You can create a user name and password so that the BlackBerry® MDS Connection Service can authenticate to LDAP
servers on behalf of BlackBerry devices.
Administration Guide
Configuring a BlackBerry MDS Connection Service to trust web servers
165