Blackberry PRD-10459-003 Administration Guide - Page 219

Con EAP-TLS configuration settings in the Wi-Fi profile on a BlackBerry device

Page 219 highlights

Administration Guide Configuring EAP-TTLS authentication After you finish: • For more information about configuration settings, see the BlackBerry Enterprise Server Policy Reference Guide. • Resend the IT policy that you assign to the user accounts to Wi-Fi enabled BlackBerry devices. • Distribute the certificates. Related topics Prerequisites: Distributing a certificate using the BlackBerry Desktop Manager, 214 Creating and configuring Wi-Fi profiles, 200 Configure EAP-TLS configuration settings in the Wi-Fi profile on a BlackBerry device If you do not configure the EAP-TLS configuration settings using the BlackBerry® Administration Service, instruct the users to configure the settings in the Wi-Fi® profile on the Wi-Fi enabled BlackBerry device. 1. On the BlackBerry device, in the device options, click Wi-Fi Connections. 2. Click the Wi-Fi profile that you want to change. 3. Click Edit. 4. If a warning about a VPN profile appears, click OK. EAP-TLS does not require a VPN profile. 5. In the Security Type list, select EAP-TLS. 6. Type the user name and password for the messaging server. 7. In the CA certificate list, click the root certificate for the certificate authority that created the authentication server certificate. 8. In the Client certificate list, click the user certificate. 9. If necessary, in the Server subject field, type the server name in the server certificate, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication. 10. If necessary, in the Server SAN field, type the alternative name for the server, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication. 11. If your organization uses dynamic IP addresses, verify that the Automatically obtain IP address and DNS option is selected. 12. Verify that the Allow inter-access point handover option is selected. 13. If necessary, select the Prompt before connection check box. If you do not select the check box, the BlackBerry device connects to an available wireless access point automatically. 14. If necessary, select the Notify on authentication failure check box. Configuring EAP-TTLS authentication If your organization implements EAP-TTLS authentication, Wi-Fi® enabled BlackBerry® devices must authenticate to an authentication server so that they can connect to the enterprise Wi-Fi network. 217

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

After you finish:
For more information about configuration settings, see the
BlackBerry Enterprise Server Policy Reference Guide
.
Resend the IT policy that you assign to the user accounts to Wi-Fi enabled BlackBerry devices.
Distribute the certificates.
Related topics
Prerequisites: Distributing a certificate using the BlackBerry Desktop Manager, 214
Creating and configuring Wi-Fi profiles, 200
Configure EAP-TLS configuration settings in the Wi-Fi profile on a
BlackBerry device
If you do not configure the EAP-TLS configuration settings using the BlackBerry® Administration Service, instruct the
users to configure the settings in the Wi-Fi® profile on the Wi-Fi enabled BlackBerry device.
1.
On the BlackBerry device, in the device options, click
Wi-Fi Connections
.
2.
Click the Wi-Fi profile that you want to change.
3.
Click
Edit
.
4.
If a warning about a VPN profile appears, click
OK
. EAP-TLS does not require a VPN profile.
5.
In the
Security Type
list, select
EAP-TLS
.
6.
Type the user name and password for the messaging server.
7.
In the
CA certificate
list, click the root certificate for the certificate authority that created the authentication
server certificate.
8.
In the
Client certificate
list, click the user certificate.
9.
If necessary, in the
Server subject
field, type the server name in the server certificate, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it
during server authentication.
10.
If necessary, in the
Server SAN
field, type the alternative name for the server, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it
during server authentication.
11.
If your organization uses dynamic IP addresses, verify that the
Automatically obtain IP address and DNS
option
is selected.
12.
Verify that the
Allow inter-access point handover
option is selected.
13.
If necessary, select the
Prompt before connection
check box. If you do not select the check box, the BlackBerry
device connects to an available wireless access point automatically.
14.
If necessary, select the
Notify on authentication failure
check box.
Configuring EAP-TTLS authentication
If your organization implements EAP-TTLS authentication, Wi-Fi® enabled BlackBerry® devices must authenticate to
an authentication server so that they can connect to the enterprise Wi-Fi network.
Administration Guide
Configuring EAP-TTLS authentication
217