Administration Guide

Configuring BlackBerry devices to enroll certificates over the wireless network

7.To assign the BlackBerry MDS Connection Service configuration set to another BlackBerry MDS Connection Service instance, repeat steps 3 to 7.

Add certificate information to a Wi-Fi profile

You must add the name of the certification authority profile that contains certificate information to a Wi-Fi profile. The name of the certification authority profile is required so that the certificate enrollment process can create a certificate that the BlackBerry device uses for Wi-Fi authentication. You can find the name of the certification authority profile in the Certificate Authority Profile Name IT policy rule.

1.In the BlackBerry Administration Service, on the BlackBerry solution management menu, expand Policy > Wi-Fi configuration.

2.Click Manage Wi-Fi profiles.

3.Click the name of the Wi-Fi profile that you want to change.

4.Click Edit profile.

5.On the Wi-Fi profile settings tab, in the Associated Certificate Authority Configuration field, type the name of the certification authority profile.

6.Click Save All.

After you finish:

Assign the Wi-Fi profile to a user account.

Assign the IT policy that includes the certificate information to the user account.

Send the IT policy to the device.

Managing an enrolled certificate

After a BlackBerry device enrolls a certificate, the CA Profile Manager monitors the certificate's expiry date and revocation status. When the expiry date approaches or the certification authority revokes the certificate, the CA Profile Manager generates a new public-private key pair, and starts the certificate enrollment process for a new certificate.

The certificate enrollment process can also start again if you change the following IT policy rules and resend the IT policy:

Certificate Authority Profile Name

Certificate Authority Type

Certificate Authority Host

Common Name Components

221

Page 221
Image 221
Blackberry SWD-20120924140022907 manual Add certificate information to a Wi-Fi profile, Managing an enrolled certificate