Blackberry PRD-10459-016 Administration Guide - Page 189

Con the BlackBerry MDS Connection Service to connect to the certificate authority

Page 189 highlights

Administration Guide Configure the BlackBerry MDS Connection Service to connect to the certificate authority 5. On the Certificate Authority Profile tab, change the appropriate values for the IT policy rules. 6. Click Save All. After you finish: For more information about the IT policy rules, see the BlackBerry Enterprise Server Policy Reference Guide. Related topics Assigning IT policies and resolving IT policy conflicts, 43 Configure the BlackBerry MDS Connection Service to connect to the certificate authority If your organization's environment includes a Microsoft® enterprise certification authority, the certification authority requires Windows® authentication, and a certification authority administrator must approve certificate requests, you must configure the BlackBerry® MDS Connection Service with the server name of the certification authority and the certification authority credentials so that the BlackBerry MDS Connection Service can send certificate requests to the certification authority. Before you begin: Create a custom template on the certification authority that does not permit the subject name to originate from information in Microsoft® Active Directory®. 1. In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view. 2. Click MDS Connection Service. 3. Click Edit component. 4. On the HTTP tab, in the Name field, type the certificate authority name. 5. In the Service URL field, type the URL that the BlackBerry MDS Connection Service can use to send certificate requests to the certification authority using the following format: http:// :/* (for example, http://myca.mycompany.com:80/*). Use /* to make sure that the BlackBerry MDS Connection Service can access all the URLs for the certification authority. 6. In the Settings section, in the User name field, type the name of a certification authority administrator account that can approve certificate requests using one of the following formats: domain\username or domain@username. 7. In the Password and Confirm password fields, type the password for the certification authority administrator account. 8. Click the Add icon. 9. Click Save all. After you finish: • Write down the URL for the certification authority that you typed in the Service URL field. You must add the that you configured in step 5 to the Certificate Authority Host IT policy rule, and the that you configured in step 5 to the Certificate Authority Port IT policy rule. 187

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432

5.
On the
Certificate Authority Profile
tab, change the appropriate values for the IT policy rules.
6.
Click
Save All
.
After you finish:
For more information about the IT policy rules, see the
BlackBerry Enterprise Server Policy Reference
Guide
.
Related topics
Assigning IT policies and resolving IT policy conflicts, 43
Configure the BlackBerry MDS Connection Service to
connect to the certificate authority
If your organization's environment includes a Microsoft® enterprise certification authority, the certification authority
requires Windows® authentication, and a certification authority administrator must approve certificate requests,
you must configure the BlackBerry® MDS Connection Service with the server name of the certification authority and
the certification authority credentials so that the BlackBerry MDS Connection Service can send certificate requests
to the certification authority.
Before you begin:
Create a custom template on the certification authority that does not permit the subject name to
originate from information in Microsoft® Active Directory®.
1.
In the BlackBerry Administration Service, on the
Servers and components
menu, expand
BlackBerry Solution
topology > BlackBerry Domain > Component view
.
2.
Click
MDS Connection Service
.
3.
Click
Edit component
.
4.
On the
HTTP
tab, in the
Name
field, type the certificate authority name.
5.
In the
Service URL
field, type the URL that the BlackBerry MDS Connection Service can use to send certificate
requests to the certification authority using the following format: http://
<FQDN_of_CA_server>
:
<port_number>
<port_number>
/* to make sure that the BlackBerry MDS Connection Service can access all the URLs for the
certification authority.
6.
In the
Settings
section, in the
User name
field, type the name of a certification authority administrator account
that can approve certificate requests using one of the following formats: domain\username or
domain@username.
7.
In the
Password
and
Confirm password
fields, type the password for the certification authority administrator
account.
8.
Click the
Add
icon.
9.
Click
Save all
.
After you finish:
Write down the URL for the certification authority that you typed in the Service URL field. You must add the
<FQDN_of_CA_server>
that you configured in step 5 to the Certificate Authority Host IT policy rule, and the
<port_number>
that you configured in step 5 to the Certificate Authority Port IT policy rule.
Administration Guide
Configure the BlackBerry MDS Connection Service to connect to the certificate authority
187