Blackberry PRD-10459-003 Administration Guide - Page 221

Con EAP-TTLS configuration settings in the Wi-Fi profile on a BlackBerry device

Page 221 highlights

Administration Guide Configuring EAP-FAST authentication Configure EAP-TTLS configuration settings in the Wi-Fi profile on a BlackBerry device If you do not configure the EAP-TTLS configuration settings using the BlackBerry® Administration Service, instruct a user to configure the settings in the Wi-Fi® profile on the Wi-Fi enabled BlackBerry device. 1. On the BlackBerry device, in the device options, click Wi-Fi Connections. 2. Click the Wi-Fi profile that you want to change. 3. Click Edit. 4. In the Security Type list, select EAP-TTLS. 5. Type the user name and password for the messaging server. 6. In the CA certificate list, click the root certificate for the certificate authority that created the authentication server certificate. 7. In the Inner link security type list, select EAP-MS-CHAPv2. 8. If necessary, in the Server subject field, type the server name in the server certificate, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication. 9. If necessary, in the Server SAN field, type the alternative name for the server, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication. 10. If your organization use dynamic IP addresses, verify that the Automatically obtain IP address and DNS option is selected. 11. Verify that the Allow inter-access point handover option is selected. 12. If necesssary, select the Prompt before connection check box. If you do not select the check box, the BlackBerry device connects to an available wireless access point automatically. 13. Verify that the Allow inter-access point handover option is selected. 14. If necessary, select the Notify on authentication failure check box. Configuring EAP-FAST authentication EAP-FAST is an authentication method that was developed by Cisco® Systems. Similar to PEAP authentication, EAPFAST authentication encrypts EAP transactions within a TLS tunnel. Although PEAP uses a server-side digital certificate to configure the TLS tunnel, EAP-FAST uses a .pac file. The .pac file that the BlackBerry® devices and the authentication server share contains secret keys that are unique to the BlackBerry devices. The EAP-FAST master key on the authentication server generates the .pac file. EAP-FAST uses the .pac file to open the TLS tunnel and authenticates the user credentials through the TLS tunnel. 219

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

Configure EAP-TTLS configuration settings in the Wi-Fi profile on a
BlackBerry device
If you do not configure the EAP-TTLS configuration settings using the BlackBerry® Administration Service, instruct a
user to configure the settings in the Wi-Fi® profile on the Wi-Fi enabled BlackBerry device.
1.
On the BlackBerry device, in the device options, click
Wi-Fi Connections
.
2.
Click the Wi-Fi profile that you want to change.
3.
Click
Edit.
4.
In the
Security Type
list, select
EAP-TTLS
.
5.
Type the user name and password for the messaging server.
6.
In the
CA certificate
list, click the root certificate for the certificate authority that created the authentication
server certificate.
7.
In the
Inner link security type
list, select
EAP-MS-CHAPv2
.
8.
If necessary, in the
Server subject
field, type the server name in the server certificate, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it
during server authentication.
9.
If necessary, in the
Server SAN
field, type the alternative name for the server, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it
during server authentication.
10.
If your organization use dynamic IP addresses, verify that the
Automatically obtain IP address and DNS
option
is selected.
11.
Verify that the
Allow inter-access point handover
option is selected.
12.
If necesssary, select the
Prompt before connection
check box. If you do not select the check box, the BlackBerry
device connects to an available wireless access point automatically.
13.
Verify that the
Allow inter-access point handover
option is selected.
14.
If necessary, select the
Notify on authentication failure check box
.
Configuring EAP-FAST authentication
EAP-FAST is an authentication method that was developed by Cisco® Systems. Similar to PEAP authentication, EAP-
FAST authentication encrypts EAP transactions within a TLS tunnel. Although PEAP uses a server-side digital certificate
to configure the TLS tunnel, EAP-FAST uses a .pac file.
The .pac file that the BlackBerry® devices and the authentication server share contains secret keys that are unique
to the BlackBerry devices. The EAP-FAST master key on the authentication server generates the .pac file. EAP-FAST
uses the .pac file to open the TLS tunnel and authenticates the user credentials through the TLS tunnel.
Administration Guide
Configuring EAP-FAST authentication
219