Installation guide
BlackBerry Enterprise Solution 27
The encrypted Notes .id password remains stored in the BlackBerry Enterprise Server for IBM Lotus Domino
messaging agent memory cache. The BlackBerry Enterprise Server administrator can customize the length of
time for which the BlackBerry Enterprise Server for IBM Lotus Domino messaging agent caches the password.
The BlackBerry Enterprise Server administrator can also set the timeout value to 0 to require the BlackBerry
device user to type the Notes .id password to decrypt and read every Lotus Notes encrypted message the user
receives on the BlackBerry device. Visit
www.blackberry.com/knowledgecenterpublic/ to view the article KB-
12420 “How to – Change the length of time for which the BlackBerry Enterprise Server for IBM Lotus Domino
messaging agent caches a Notes .id password” for more information on customizing the length of time for which
the BlackBerry Enterprise Server for IBM Lotus Domino messaging agent caches the password.
The BlackBerry device deletes the Notes .id files and plain text passwords from BlackBerry device memory when
• a message decryption failure occurs on the BlackBerry device
• the BlackBerry device resets
• the password times out (the default expiration timeout period is 24 hours)
If a BlackBerry device user types more than ten consecutive incorrect passwords on the BlackBerry device within
one hour, the BlackBerry Enterprise Server for IBM Lotus Domino messaging agent makes secure messaging
unavailable to that BlackBerry device user for one hour.
The temporary disabling period increases by ten minute increments to a limit of 24 hours. It increments each
time a BlackBerry device user exceeds the maximum number of failed password attempts, and defaults back to
one hour when the user types the correct password.
When secure messaging is temporarily unavailable, a BlackBerry device user can manually re-enable secure
messaging by importing the Notes .id file, or changing the Notes .id password using the BlackBerry Desktop
Software or the Domino Web Access client.
Protecting stored data
Protecting stored messages on the messaging server
The IBM Lotus Domino server and the Microsoft Exchange server perform all message storage and specific user
data storage in their environments. In the Novell GroupWise server environment, the Post-Office Agent where a
user’s messaging account resides stores messages and user data.
Messaging server Message storage location
IBM Lotus Domino server IBM Lotus Domino databases within the IBM Lotus Domino environment
Microsoft Exchange server Hidden folders in Microsoft Exchange mailboxes that are associated with a
user
Storing message and user data in IBM Lotus Domino databases
The BlackBerry Enterprise Server creates and uses the following IBM Lotus Domino databases to manage
BlackBerry device messages:
Database Message storage method
BlackBerry state Stores an entry that establishes a connection between each original message in a
user’s IBM Lotus Notes Inbox and the same message on that user’s BlackBerry device
Each BlackBerry device user has a uniquely named BlackBerry state database.
www.blackberry.com