9. If necesssary, in the Server subject field, type the server name in the server certificate, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during
server authentication.
10. If necesssary, in the Server SAN field, type the alternative name for the server, in URL format (for example,
server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during
server authentication.
11. If your organization uses dynamic IP addresses, verify that the Automatically obtain IP address and DNS option is
selected.
12. Verify that the Allow inter-access point handover option is selected.
13. If necesssary, select the Prompt before connection check box. If you do not select the check box, the BlackBerry
device connects to an available wireless access point automatically.
14. If necesssary, select the Notify on authentication failure check box.
15. If necesssary, select the VPN profile.
Configuring EAP-TLS authentication
If your organization implements EAP-TLS authentication, Wi-Fi enabled BlackBerry devices must authenticate to an
authentication server so that they can connect to the enterprise Wi-Fi network.
EAP-TLS authentication requires that BlackBerry devices trust the authentication server certificate and use a client-side
certificate as the supplicant credentials. To trust the authentication server certificate, BlackBerry devices must trust the
certificate authority that issued the certificate. A certificate authority that the BlackBerry devices and the authentication
server trust mutually must generate the certificate for the authentication server and the certificate for each BlackBerry
device.
BlackBerry devices that use EAP-TLS authentication require a client certificate and the root certificate for the certificate
authority server that created the certificate for the authentication server. You can obtain and install both certificates using
the same distribution method.
To distribute the certificates to BlackBerry devices, you can use the certificate synchronization tool in the BlackBerry
Desktop Manager, or you can enroll the certificate over the wireless network. You must configure a Wi-Fi profile to provide
the user name and password for authentication.
For more information about how the BlackBerry Enterprise Solution supports EAP-TLS authentication, see the BlackBerry
Enterprise Server Security Technical Overview.
Administration Guide Configuring encryption and authentication methods for Wi-Fi enabled BlackBerry devices
254