Administration Guide

Configuring encryption and authentication methods for Wi-Fi enabled BlackBerry devices

Configure EAP-TLS configuration settings in the Wi-Fi profile on a BlackBerry device

If you do not configure the EAP-TLS configuration settings using the BlackBerry Administration Service, instruct the users to configure the settings in the Wi-Fi profile on the Wi-Fi enabled BlackBerry device.

1.On the BlackBerry device, in the device options, click Wi-Fi Connections.

2.Click the Wi-Fi profile that you want to change.

3.Click Edit.

4.If a warning about a VPN profile appears, click OK. EAP-TLS does not require a VPN profile.

5.In the Security Type list, select EAP-TLS.

6.Type the user name and password for the messaging server.

7.In the CA certificate list, click the root certificate for the certificate authority that created the authentication server certificate.

8.In the Client certificate list, click the user certificate.

9.If necessary, in the Server subject field, type the server name in the server certificate, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication.

10.If necessary, in the Server SAN field, type the alternative name for the server, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication.

11.If your organization uses dynamic IP addresses, verify that the Automatically obtain IP address and DNS option is selected.

12.Verify that the Allow inter-access point handover option is selected.

13.If necessary, select the Prompt before connection check box. If you do not select the check box, the BlackBerry device connects to an available wireless access point automatically.

14.If necessary, select the Notify on authentication failure check box.

Configuring EAP-TTLS authentication

If your organization implements EAP-TTLS authentication, Wi-Fi enabled BlackBerry devices must authenticate to an authentication server so that they can connect to the enterprise Wi-Fi network.

256

Page 256
Image 256
Blackberry SWD-20120924140022907 manual Configuring EAP-TTLS authentication