Blackberry PRD-10459-016 Administration Guide - Page 57

Con the BlackBerry Enterprise Solution to support S/MIME encryption

Page 57 highlights

Administration Guide Extending messaging security to a BlackBerry device The BlackBerry device user uses the S/MIME private key to decrypt S/MIME-protected messages on the BlackBerry device and to sign, encrypt, and send S/MIME-protected messages from the BlackBerry device. If the BlackBerry® Enterprise Server receives an S/MIME-encrypted message but the BlackBerry device user did not install the S/MIME Support Package for BlackBerry smartphones, the BlackBerry Enterprise Server sends a message to the BlackBerry device to indicate that the BlackBerry device does not support S/MIME-encrypted messages. After the BlackBerry device user installs the S/MIME Support Package for BlackBerry smartphones, the BlackBerry device user can synchronize and manage S/MIME certificates and S/MIME private keys using the certificate synchronization tool of the BlackBerry® Desktop Manager. The BlackBerry Enterprise Server does not apply an appended disclaimer to S/MIME-protected messages that the BlackBerry device user sends from the BlackBerry device. Digital signatures on S/MIME-protected messages that the BlackBerry device sends are not valid if disclaimers are appended to the messages. To require the BlackBerry device user to use S/MIME encryption when forwarding or replying to messages, you can configure the S/MIME Force Digital Signature IT policy rule and the S/MIME Force Encrypted Messages IT policy rule. The S/MIME Support Package for BlackBerry smartphones is also designed to support the following features: • encoding and decoding of Unicode messages • ability to use a password, which the sender and recipient each know, to encrypt S/MIME-protected email messages or PIN messages • ability to read S/MIME certificates that are stored on a smart card Configure the BlackBerry Enterprise Solution to support S/MIME encryption 1. Configure encryption options for S/MIME-protected messages on the BlackBerry® Enterprise Server. 2. If required, configure message classifications for email messages. 3. If required, configure the BlackBerry MDS Connection Service to retrieve certificates and the status of certificates from LDAP servers, DSML certificate servers, OCSP servers, or CRL servers. 4. Instruct users to install the S/MIME Support Package for BlackBerry® smartphones on BlackBerry devices. 5. Perform one of the following tasks: • Instruct users to add the Certificate Synchronization Manager to the BlackBerry® Desktop Manager so that the BlackBerry Desktop Manager can manage certificates for the BlackBerry devices. • Configure the BlackBerry Enterprise Server to permit users to enroll certificates over the wireless network. Related topics Configuring certificate server information for the BlackBerry MDS Connection Service, 166 Enforcing secure messaging using classifications, 57 Configuring BlackBerry devices to enroll certificates over the wireless network, 186 Configure encryption options for S/MIME-protected messages You can configure encryption options to control how the BlackBerry® Enterprise Server processes S/MIME-protected messages. 1. In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view > Email. 2. Click the instance that you want to change. 55

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432

The BlackBerry device user uses the S/MIME private key to decrypt S/MIME-protected messages on the BlackBerry
device and to sign, encrypt, and send S/MIME-protected messages from the BlackBerry device. If the BlackBerry®
Enterprise Server receives an S/MIME-encrypted message but the BlackBerry device user did not install the S/MIME
Support Package for BlackBerry smartphones, the BlackBerry Enterprise Server sends a message to the BlackBerry
device to indicate that the BlackBerry device does not support S/MIME-encrypted messages.
After the BlackBerry device user installs the S/MIME Support Package for BlackBerry smartphones, the BlackBerry
device user can synchronize and manage S/MIME certificates and S/MIME private keys using the certificate
synchronization tool of the BlackBerry® Desktop Manager. The BlackBerry Enterprise Server does not apply an
appended disclaimer to S/MIME-protected messages that the BlackBerry device user sends from the BlackBerry
device. Digital signatures on S/MIME-protected messages that the BlackBerry device sends are not valid if disclaimers
are appended to the messages.
To require the BlackBerry device user to use S/MIME encryption when forwarding or replying to messages, you can
configure the S/MIME Force Digital Signature IT policy rule and the S/MIME Force Encrypted Messages IT policy rule.
The S/MIME Support Package for BlackBerry smartphones is also designed to support the following features:
encoding and decoding of Unicode messages
ability to use a password, which the sender and recipient each know, to encrypt S/MIME-protected email
messages or PIN messages
ability to read S/MIME certificates that are stored on a smart card
Configure the BlackBerry Enterprise Solution to support S/MIME encryption
1.
Configure encryption options for S/MIME-protected messages on the BlackBerry® Enterprise Server.
2.
If required, configure message classifications for email messages.
3.
If required, configure the BlackBerry MDS Connection Service to retrieve certificates and the status of certificates
from LDAP servers, DSML certificate servers, OCSP servers, or CRL servers.
4.
Instruct users to install the S/MIME Support Package for BlackBerry® smartphones on BlackBerry devices.
5.
Perform one of the following tasks:
Instruct users to add the Certificate Synchronization Manager to the BlackBerry® Desktop Manager so that
the BlackBerry Desktop Manager can manage certificates for the BlackBerry devices.
Configure the BlackBerry Enterprise Server to permit users to enroll certificates over the wireless network.
Related topics
Configuring certificate server information for the BlackBerry MDS Connection Service, 166
Enforcing secure messaging using classifications, 57
Configuring BlackBerry devices to enroll certificates over the wireless network, 186
Configure encryption options for S/MIME-protected messages
You can configure encryption options to control how the BlackBerry® Enterprise Server processes S/MIME-protected
messages.
1.
In the BlackBerry Administration Service, on the
Servers and components
menu, expand
BlackBerry Solution
topology > BlackBerry Domain > Component view > Email
.
2.
Click the instance that you want to change.
Administration Guide
Extending messaging security to a BlackBerry device
55