Blackberry PRD-10459-003 Administration Guide - Page 60

Enforcing secure messaging using classifications, Create a message classification

Page 60 highlights

Administration Guide Enforcing secure messaging using classifications After you finish: • To stop a BlackBerry Enterprise Server from importing Lotus Notes .id files, type traittool.exe -server -trait EnableNNEIDFileProvisioning -set false, where is the name of the BlackBerry Enterprise Server instance. • To stop all BlackBerry Enterprise Server instances from importing the Lotus Notes .id files, type traittool.exe global -trait EnableNNEIDFileProvisioning -set false. Turning off support for IBM Lotus Notes encryption To turn off support for decrypting IBM® Lotus Notes® encrypted messages and S/MIME-encrypted messages on BlackBerry® devices, users can detach their Notes .id files from their mail files using the BlackBerry® Desktop Software or IBM® Lotus® Domino® Web Access software. For more information about turning off support for decrypting IBM Lotus Notes encrypted messages and S/MIMEencrypted messages, see the online help that is available in the BlackBerry® Desktop Software. Enforcing secure messaging using classifications You can use message classifications to require S/MIME-enabled users or PGP® enabled users to sign, encrypt, or sign and encrypt email messages that they send from the BlackBerry® devices. You use the Message Classification IT policy rule to configure one or more message classifications that users can apply to email messages. The message classification that the users select when they compose email messages determines the type of S/MIME message protection or PGP message protection that applies to the email messages. If a user does not select a message classification, by default, the BlackBerry device applies the first classification in the message classification list on the BlackBerry device. You can change the order that the BlackBerry device lists the classifications in. The message protection options on the BlackBerry device are limited to the types of encryption and digitial signing that the highly secure messaging packages on the BlackBerry device permit. When a user applies a message classification to an email message on a BlackBerry device, the user must select one type of message protection that the message classification permits, or accept the default type of message protection. If a user selects a message classification that requires signing, encryption, or signing and encryption of the email message, and the user did not install a highly secure messaging package on the BlackBerry device, the user cannot send the email message. Create a message classification 1. In the BlackBerry® Administration Service, on the BlackBerry solution management menu, expand Policy. 2. Click Manage IT policies. 3. In the list of IT policies, click an IT policy. 4. Click Edit IT policy. 5. On the Security tab, at the bottom of the screen, in the Message Classification Display Name field, type a display name that you want to appear in the Classifications list on BlackBerry devices. 58

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

After you finish:
To stop a BlackBerry Enterprise Server from importing Lotus Notes .id files, type
traittool.exe -server
<instance_name>
-trait EnableNNEIDFileProvisioning -set false
, where
<instance_name>
is the name of the
BlackBerry Enterprise Server instance.
To stop all BlackBerry Enterprise Server instances from importing the Lotus Notes .id files, type
traittool.exe -
global -trait EnableNNEIDFileProvisioning -set false
.
Turning off support for IBM Lotus Notes encryption
To turn off support for decrypting IBM® Lotus Notes® encrypted messages and S/MIME-encrypted messages on
BlackBerry® devices, users can detach their Notes .id files from their mail files using the BlackBerry® Desktop Software
or IBM® Lotus® Domino® Web Access software.
For more information about turning off support for decrypting IBM Lotus Notes encrypted messages and S/MIME-
encrypted messages, see the online help that is available in the BlackBerry® Desktop Software.
Enforcing secure messaging using classifications
You can use message classifications to require S/MIME-enabled users or PGP® enabled users to sign, encrypt, or sign
and encrypt email messages that they send from the BlackBerry® devices.
You use the Message Classification IT policy rule to configure one or more message classifications that users can
apply to email messages. The message classification that the users select when they compose email messages
determines the type of S/MIME message protection or PGP message protection that applies to the email messages.
If a user does not select a message classification, by default, the BlackBerry device applies the first classification in
the message classification list on the BlackBerry device. You can change the order that the BlackBerry device lists the
classifications in.
The message protection options on the BlackBerry device are limited to the types of encryption and digitial signing
that the highly secure messaging packages on the BlackBerry device permit. When a user applies a message
classification to an email message on a BlackBerry device, the user must select one type of message protection that
the message classification permits, or accept the default type of message protection. If a user selects a message
classification that requires signing, encryption, or signing and encryption of the email message, and the user did not
install a highly secure messaging package on the BlackBerry device, the user cannot send the email message.
Create a message classification
1.
In the BlackBerry® Administration Service, on the
BlackBerry solution management
menu, expand
Policy
.
2.
Click
Manage IT policies
.
3.
In the list of IT policies, click an IT policy.
4.
Click
Edit IT policy
.
5.
On the
Security
tab, at the bottom of the screen, in the
Message Classification Display Name
field, type a display
name that you want to appear in the Classifications list on BlackBerry devices.
Administration Guide
Enforcing secure messaging using classifications
58