Administration Guide

Configuring encryption and authentication methods for Wi-Fi enabled BlackBerry devices

For more information about configuration settings, see the BlackBerry Enterprise Server Policy Reference Guide.

Resend the IT policy that you assign to the user accounts to Wi-Fi enabled BlackBerry devices.

Distribute the certificates.

Related information

Prerequisites: Distributing a certificate using the BlackBerry Desktop Manager, 252

Creating and configuring Wi-Fi profiles, 235

Configure EAP-TTLS configuration settings in the Wi-Fi profile on a BlackBerry device

If you do not configure the EAP-TTLS configuration settings using the BlackBerry Administration Service, instruct a user to configure the settings in the Wi-Fi profile on the Wi-Fi enabled BlackBerry device.

1.On the BlackBerry device, in the device options, click Wi-Fi Connections.

2.Click the Wi-Fi profile that you want to change.

3.Click Edit.

4.In the Security Type list, select EAP-TTLS.

5.Type the user name and password for the messaging server.

6.In the CA certificate list, click the root certificate for the certificate authority that created the authentication server certificate.

7.In the Inner link security type list, select EAP-MS-CHAPv2.

8.If necessary, in the Server subject field, type the server name in the server certificate, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication.

9.If necessary, in the Server SAN field, type the alternative name for the server, in URL format (for example, server1.domain.com or server1.domain.net). If you leave the field blank, the BlackBerry device skips over it during server authentication.

10.If your organization use dynamic IP addresses, verify that the Automatically obtain IP address and DNS option is selected.

11.Verify that the Allow inter-access point handover option is selected.

12.If necesssary, select the Prompt before connection check box. If you do not select the check box, the BlackBerry device connects to an available wireless access point automatically.

13.Verify that the Allow inter-access point handover option is selected.

14.If necessary, select the Notify on authentication failure check box.

258

Page 258
Image 258
Blackberry SWD-20120924140022907 Security Type list, select EAP-TTLS, Inner link security type list, select EAP-MS-CHAPv2