Blackberry PRD-10459-003 Administration Guide - Page 218

Configuring EAP-TLS authentication

Page 218 highlights

Administration Guide Configuring EAP-TLS authentication Configuring EAP-TLS authentication If your organization implements EAP-TLS authentication, Wi-Fi® enabled BlackBerry® devices must authenticate to an authentication server so that they can connect to the enterprise Wi-Fi network. EAP-TLS authentication requires that BlackBerry devices trust the authentication server certificate and use a clientside certificate as the supplicant credentials. To trust the authentication server certificate, BlackBerry devices must trust the certificate authority that issued the certificate. A certificate authority that the BlackBerry devices and the authentication server trust mutually must generate the certificate for the authentication server and the certificate for each BlackBerry device. BlackBerry devices that use EAP-TLS authentication require a client certificate and the root certificate for the certificate authority server that created the certificate for the authentication server. You can obtain and install both certificates using the same distribution method. To distribute the certificates to BlackBerry devices, you can use the certificate synchronization tool in the BlackBerry® Desktop Manager, or you can enroll the certificate over the wireless network. You must configure a Wi-Fi profile to provide the user name and password for authentication. For more information about how the BlackBerry® Enterprise Solution supports EAP-TLS authentication, see the BlackBerry Enterprise Server Security Technical Overview. Configure EAP-TLS authentication data for BlackBerry devices using a WiFi profile If BlackBerry® users in your organization's environment use BlackBerry® 7270 smartphones, you must configure user names and passwords using IT policy rules instead of configuration settings. 1. In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand Policy > WiFi configuration. 2. Click Manage Wi-Fi profiles. 3. Click the name of the Wi-Fi® profile that you want to change. 4. Click Edit profile. 5. On the Wi-Fi profile settings tab, perform the following actions: • In the Wi-Fi User Name field, type the user name for EAP-TLS authentication. • In the Wi-Fi User Password field, type the password for EAP-TLS authentication. 6. If required, configure the following configuration settings: • Wi-Fi Link Security • Wi-Fi Hard Token Required • Wi-Fi Server Subject • Wi-Fi Server SAN • Wi-Fi Disable Server Certificate Validation 7. Click Save All. 216

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

Configuring EAP-TLS authentication
If your organization implements EAP-TLS authentication, Wi-Fi® enabled BlackBerry® devices must authenticate to
an authentication server so that they can connect to the enterprise Wi-Fi network.
EAP-TLS authentication requires that BlackBerry devices trust the authentication server certificate and use a client-
side certificate as the supplicant credentials. To trust the authentication server certificate, BlackBerry devices must
trust the certificate authority that issued the certificate. A certificate authority that the BlackBerry devices and the
authentication server trust mutually must generate the certificate for the authentication server and the certificate
for each BlackBerry device.
BlackBerry devices that use EAP-TLS authentication require a client certificate and the root certificate for the
certificate authority server that created the certificate for the authentication server. You can obtain and install both
certificates using the same distribution method.
To distribute the certificates to BlackBerry devices, you can use the certificate synchronization tool in the BlackBerry®
Desktop Manager, or you can enroll the certificate over the wireless network. You must configure a Wi-Fi profile to
provide the user name and password for authentication.
For more information about how the BlackBerry® Enterprise Solution supports EAP-TLS authentication, see the
BlackBerry Enterprise Server Security Technical Overview
.
Configure EAP-TLS authentication data for BlackBerry devices using a Wi-
Fi profile
If BlackBerry® users in your organization's environment use BlackBerry® 7270 smartphones, you must configure user
names and passwords using IT policy rules instead of configuration settings.
1.
In the BlackBerry Administration Service, on the
BlackBerry solution management
menu, expand
Policy > Wi-
Fi configuration
.
2.
Click
Manage Wi-Fi profiles
.
3.
Click the name of the Wi-Fi® profile that you want to change.
4.
Click
Edit profile
.
5.
On the
Wi-Fi profile settings
tab, perform the following actions:
In the
Wi-Fi User Name
field, type the user name for EAP-TLS authentication.
In the
Wi-Fi User Password
field, type the password for EAP-TLS authentication.
6.
If required, configure the following configuration settings:
Wi-Fi Link Security
Wi-Fi Hard Token Required
Wi-Fi Server Subject
Wi-Fi Server SAN
Wi-Fi Disable Server Certificate Validation
7.
Click
Save All
.
Administration Guide
Configuring EAP-TLS authentication
216