Administration Guide

Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop

 

Manager

screen and access the BlackBerry Administration Service and BlackBerry Web Desktop Manager directly. The BlackBerry Monitoring Service does not support single sign-on authentication.

Before you turn on single sign-on, you must configure constrained delegation for the Microsoft Active Directory account for the BlackBerry Administration Service.

Configure constrained delegation for the Microsoft Active Directory account to support single sign-on authentication

1.Use the Windows Server ADSI Edit tool to add the following SPNs for the BlackBerry Administration Service pool to the Microsoft Active Directory account :

HTTP/<BAS_pool_FQDN> (for example, HTTP/BASconsole104.example.com)

BASPLUGIN111/<BAS_pool_FQDN> (for example, BASPLUGIN111/BASconsole104.example.com)

2.If you create separate pools of BlackBerry Administration Service instances and BlackBerry Web Desktop Manager instances in the BlackBerry Administration Service pool, add the HTTP/<BAS_pool_FQDN> SPN for each pool to the Microsoft Active Directory account.

3.Configure the Microsoft Active Directory account for constrained delegation using the following settings:

trust this user for delegation to specific services only

use Kerberos only

4.In the Microsoft Active Directory account properties, on the Delegation tab, add BASPLUGIN111/ <BAS_pool_FQDN> to the list of services.

After you finish: For more information about configuring constrained delegation for the Microsoft Active Directory account so you can access the BlackBerry Administration Service, visit www.blackberry.com/btsc to read article KB22717.

Turn on single sign-on authentication for the BlackBerry Administration Service

1.In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.

2.Click BlackBerry Administration Service.

3.On the Microsoft® Active Directory® authentication tab, click Edit component.

270

Page 270
Image 270
Blackberry SWD-20120924140022907 manual 270