Blackberry PRD-10459-003 Administration Guide - Page 228

Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop Manager, Import a new SSL certificate for the BlackBerry Administration Service and BlackBerry Web Desktop Manager

Page 228 highlights

Administration Guide Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop Manager Changing the security settings of the 22 BlackBerry Administration Service and BlackBerry Web Desktop Manager Import a new SSL certificate for the BlackBerry Administration Service and BlackBerry Web Desktop Manager When you install the BlackBerry® Administration Service and BlackBerry® Web Desktop Manager, the setup application generates an SSL certificate to protect the HTTPS connection. You can import a self-signed SSL certificate or a trusted certificate that a certification authority signs after the installation process completes. If you configure a BlackBerry Administration Service pool, you must generate an SSL certificate that uses the name of the BlackBerry Administration Service pool. For more information about using the keytool, visit java.sun.com/javase/6/docs/technotes/tools/windows/ keytool.html. Before you begin: If you want to use a trusted certificate, copy the root certificate of the certification authority to the computer that hosts the BlackBerry Administration Service. 1. On a computer that hosts a BlackBerry Administration Service instance, in :\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore, back up the web.keystore file. 2. Using the keytool in :\Program Files\Java\\bin, delete the default SSL certificate that the setup application generated (for example, keytool -delete -alias httpssl -keystore ":\Program Files \Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore"). 3. Using the keytool and the SSL password that you specified when you installed the BlackBerry Administration Service, generate a new entry and private key in the web.keystore file (for example, keytool -genkey -alias httpssl -keypass -keystore ":\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS \bin\web.keystore"). When the keytool prompts you for the first name and last name, type the pool name of the BlackBerry Administration Service. You can find the pool name in the Administration Service - High Availability tab. 4. If you want to use a trusted certificate, using the keytool, import the root certificate of the certification authority (for example, keytool -import -alias -file .cer -trustcacerts -keystore ":\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore"). 5. Using the keytool, generate a certificate signing request (for example, keytool -certreq -alias httpssl -file .csr -keystore ":\Program Files\Research In Motion\BlackBerry Enterprise Server \BAS\bin\web.keystore"). 6. Send the certificate signing request to a certification authority so that the certification authority can create the certificate. 7. When the certification authority returns the certificate, copy it into a text file and save it with a .cer extension. 226

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

Changing the security settings of the
BlackBerry Administration Service and
BlackBerry Web Desktop Manager
22
Import a new SSL certificate for the BlackBerry
Administration Service and BlackBerry Web Desktop
Manager
When you install the BlackBerry® Administration Service and BlackBerry® Web Desktop Manager, the setup
application generates an SSL certificate to protect the HTTPS connection. You can import a self-signed SSL certificate
or a trusted certificate that a certification authority signs after the installation process completes. If you configure a
BlackBerry Administration Service pool, you must generate an SSL certificate that uses the name of the BlackBerry
Administration Service pool.
For more information about using the keytool, visit
java.sun.com/javase/6/docs/technotes/tools/windows/
keytool.html
.
Before you begin:
If you want to use a trusted certificate, copy the root certificate of the certification authority to
the computer that hosts the BlackBerry Administration Service.
1.
On a computer that hosts a BlackBerry Administration Service instance, in
<drive>
:\Program Files\Research In
Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore, back up the
web.keystore
file.
2.
Using the keytool in
<drive>
:\Program Files\Java\
<JRE_version>
\bin, delete the default SSL certificate that the
setup application generated (for example, keytool -delete -alias httpssl -keystore "
<drive>
:\Program Files
\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore").
3.
Using the keytool and the SSL password that you specified when you installed the BlackBerry Administration
Service, generate a new entry and private key in the web.keystore file (for example, keytool -genkey -alias httpssl
-keypass
<password>
-keystore "
<drive>
:\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS
\bin\web.keystore"). When the keytool prompts you for the first name and last name, type the pool name of
the BlackBerry Administration Service. You can find the pool name in the
Administration Service – High
Availability
tab.
4.
If you want to use a trusted certificate, using the keytool, import the root certificate of the certification authority
(for example, keytool -import -alias
<ca_alias_name>
-file
<root_certificate_file>
.cer -trustcacerts -keystore
"
<drive>
:\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore").
5.
Using the keytool, generate a certificate signing request (for example, keytool -certreq -alias httpssl -file
<certreq_filename>
.csr -keystore "
<drive>
:\Program Files\Research In Motion\BlackBerry Enterprise Server
\BAS\bin\web.keystore").
6.
Send the certificate signing request to a certification authority so that the certification authority can create the
certificate.
7.
When the certification authority returns the certificate, copy it into a text file and save it with a .cer extension.
Administration Guide
Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop
Manager
226