Blackberry PRD-10459-016 Administration Guide - Page 230

Configuring Microsoft Active Directory authentication in an environment that includes a resource

Page 230 highlights

Administration Guide Configuring Microsoft Active Directory authentication in an environment that includes a resource forest 8. Using the keytool, import the certificate to the web.keystore file (for example, keytool -import -alias httpssl keystore ":\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore" -file ".cer"). 9. In the Windows® Services, restart the BlackBerry Administration Service services. 10. Complete the following actions on each computer that hosts a BlackBerry Administration Service instance: a. Copy the web.keystore file in the :\Program Files\Research In Motion\BlackBerry Enterprise Server \BAS\bin folder from the BlackBerry Administration Service that you updated to the other BlackBerry Administration Service instances. b. In the Windows® registry, copy the WebKeyStorePass value in the HKEY_CURRENT_USER\Software \Research In Motion\BlackBerry Enterprise Server\Administration Service\Key Store from the BlackBerry Administration Service that you updated to the other BlackBerry Administration Service instances. c. In the Windows Services, restart the BlackBerry Administration Service services. Related topics Restarting BlackBerry Enterprise Server components, 330 Configuring Microsoft Active Directory authentication in an environment that includes a resource forest If your organization's environment includes a resource forest that is dedicated to running Microsoft® Exchange, you can configure the BlackBerry® Administration Service to use Microsoft® Active Directory® authentication to log in BlackBerry device users that have user accounts that are located in trusted account forests. The BlackBerry Administration Service can use Microsoft Active Directory authentication to log users into the BlackBerry Administration Service console and the BlackBerry® Web Desktop Manager. You must install the BlackBerry® Enterprise Server in the resource forest if a resource forest exists in your organization's environment. In the resource forest, you create a mailbox for each user account and associate the mailboxes with the user accounts that are located in the account forests. When you associate the mailboxes in the resource forest with the user accounts in the account forests, the user accounts obtain full access to the mailboxes and the user accounts in the account forests are connected to the Microsoft Exchange server. To authenticate users who log in to the BlackBerry Administration Service or BlackBerry Web Desktop Manager, the BlackBerry Administration Service must read the user information that is stored in the global catalog servers that are part of the resource forest. To configure the BlackBerry Administration Service to authenticate user accounts that are associated with mailboxes in the resource forest, you must create a Microsoft Active Directory account for the BlackBerry Administration Service that is located in a Windows® domain that is part of the resource forest. During the BlackBerry Enterprise Server installation process, you provide the Windows domain, user name, and password for the Microsoft Active Directory account, and, if required, the names of the global catalog servers that the BlackBerry Administration Service can use. You can change the Windows domain, user name, and password for the Microsoft Active Directory account and global catalog servers after the installation process completes. For more information, visit technet.microsoft.com to read Using a Dedicated Exchange forest. Related topics Restarting BlackBerry Enterprise Server components, 330 228

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432

8.
Using the keytool, import the certificate to the web.keystore file (for example, keytool -import -alias httpssl -
keystore "
<drive>
:\Program Files\Research In Motion\BlackBerry Enterprise Server\BAS\bin\web.keystore" -file
"
<certificate_filename>
.cer").
9.
In the Windows® Services, restart the BlackBerry Administration Service services.
10.
Complete the following actions on each computer that hosts a BlackBerry Administration Service instance:
a.
Copy the web.keystore file in the
<drive>
:\Program Files\Research In Motion\BlackBerry Enterprise Server
\BAS\bin folder from the BlackBerry Administration Service that you updated to the other BlackBerry
Administration Service instances.
b.
In the Windows® registry, copy the WebKeyStorePass value in the HKEY_CURRENT_USER\Software
\Research In Motion\BlackBerry Enterprise Server\Administration Service\Key Store from the BlackBerry
Administration Service that you updated to the other BlackBerry Administration Service instances.
c.
In the Windows Services, restart the BlackBerry Administration Service services.
Related topics
Restarting BlackBerry Enterprise Server components, 330
Configuring Microsoft Active Directory authentication in an
environment that includes a resource forest
If your organization's environment includes a resource forest that is dedicated to running Microsoft® Exchange, you
can configure the BlackBerry® Administration Service to use Microsoft® Active Directory® authentication to log in
BlackBerry device users that have user accounts that are located in trusted account forests. The BlackBerry
Administration Service can use Microsoft Active Directory authentication to log users into the BlackBerry
Administration Service console and the BlackBerry® Web Desktop Manager.
You must install the BlackBerry® Enterprise Server in the resource forest if a resource forest exists in your
organization's environment. In the resource forest, you create a mailbox for each user account and associate the
mailboxes with the user accounts that are located in the account forests. When you associate the mailboxes in the
resource forest with the user accounts in the account forests, the user accounts obtain full access to the mailboxes
and the user accounts in the account forests are connected to the Microsoft Exchange server.
To authenticate users who log in to the BlackBerry Administration Service or BlackBerry Web Desktop Manager, the
BlackBerry Administration Service must read the user information that is stored in the global catalog servers that are
part of the resource forest. To configure the BlackBerry Administration Service to authenticate user accounts that
are associated with mailboxes in the resource forest, you must create a Microsoft Active Directory account for the
BlackBerry Administration Service that is located in a Windows® domain that is part of the resource forest. During
the BlackBerry Enterprise Server installation process, you provide the Windows domain, user name, and password
for the Microsoft Active Directory account, and, if required, the names of the global catalog servers that the BlackBerry
Administration Service can use. You can change the Windows domain, user name, and password for the Microsoft
Active Directory account and global catalog servers after the installation process completes.
For more information, visit
technet.microsoft.com
to read
Using a Dedicated Exchange forest
.
Related topics
Restarting BlackBerry Enterprise Server components, 330
Administration Guide
Configuring Microsoft Active Directory authentication in an environment that includes a resource
forest
228