Installation guide
BlackBerry Enterprise Solution Security
Protecting stored data 21
• the BlackBerry Enterprise Server restarts
• the password times out (the default expiration timeout is 24 hours)
The encrypted Notes .id password remains stored in the BlackBerry Enterprise Server for IBM Lotus Domino
messaging agent memory cache.
The BlackBerry device deletes the Notes .id files and plain text passwords from BlackBerry device memory when
• a message decryption failure occurs on the BlackBerry device
• the BlackBerry device resets
• the password times out (the default expiration timeout period is 24 hours)
If a user types more than ten consecutive incorrect passwords within one hour, the BlackBerry Enterprise Server
for IBM Lotus Domino messaging agent makes secure messaging unavailable to that user for one hour.
The temporary disabling period increases by ten minute increments to a limit of 24 hours. It increments each
time a user exceeds the maximum number of failed password attempts and then defaults back to one hour.
When secure messaging is temporarily unavailable, a user can manually re-enable secure messaging by
importing the Notes .id file, or changing their Notes .id password using the BlackBerry Desktop Software or the
Domino Web Access client.
Protecting stored data
Protecting stored messages on the messaging server
The IBM Lotus Domino server and the Microsoft Exchange server perform all message storage and specific user
data storage in their environments. In the Novell GroupWise server environment, the Post-Office Agent where a
user’s messaging account resides stores messages and user data.
Messaging server Message storage location
IBM Lotus Domino server IBM Lotus Domino databases within the IBM Lotus Domino environment
Microsoft Exchange server Hidden folders in Microsoft Exchange mailboxes that are associated with a
user
Storing message and user data in IBM Lotus Domino databases
The BlackBerry Enterprise Server creates and uses the following IBM Lotus Domino databases to manage
BlackBerry device messages:
Database Message storage method
BlackBerry state
• stores an entry that establishes a connection between each original message in a
user’s IBM Lotus Notes Inbox and the same message on that user’s BlackBerry
device
Note: Each BlackBerry user has a uniquely named BlackBerry state database.
BlackBerry profiles
• stores important configuration information for each user, including the
BlackBerry device identification information and master encryption key
• stores a link to a user’s BlackBerry state database and stores other information
that the BlackBerry Enterprise Server uses to manage the flow of messages to
and from the BlackBerry device
www.blackberry.com