Installation guide
BlackBerry Enterprise Solution
BlackBerry architecture component security .................................................................................................... 33
BlackBerry Infrastructure .................................................................................................................................33
BlackBerry Enterprise Server ...........................................................................................................................34
Messaging server ...............................................................................................................................................34
BlackBerry Configuration Database ...............................................................................................................34
BlackBerry MDS Services databases ..............................................................................................................36
Protecting the BlackBerry Enterprise Solution connections........................................................................... 37
SRP authentication ............................................................................................................................................ 37
How the BlackBerry Enterprise Server and the BlackBerry Infrastructure handle undeliverable
messages .............................................................................................................................................................38
BlackBerry Router protocol authentication...................................................................................................39
Authentication during wireless enterprise activation .................................................................................40
TCP/IP connection..............................................................................................................................................41
Messaging server to computer email application connection ...................................................................42
Connections between the BlackBerry Desktop Manager and its components .......................................42
BlackBerry MDS connections...........................................................................................................................43
Using two-factor authentication to protect connections to enterprise Wi-Fi networks........................45
How the BlackBerry Enterprise Solution authenticates requests for wireless software upgrades......45
WAP gateway connections ...............................................................................................................................46
Instant messaging server connections...........................................................................................................46
Using segmented network architecture to prevent the spread of malware on your organization’s
network ................................................................................................................................................................46
Protecting Wi-Fi connections to the BlackBerry Enterprise Solution............................................................47
Enterprise Wi-Fi network solution architecture security features.............................................................47
Accessing the BlackBerry Infrastructure .......................................................................................................48
Supported security features of Wi-Fi enabled BlackBerry devices............................................................48
IEEE 802.1X environment components.......................................................................................................... 49
How the IEEE 802.1x environment controls access to the enterprise Wi-Fi network............................ 49
Administering enterprise Wi-Fi network solution security using IT policy rules.....................................50
Requiring protected connections to enterprise Wi-Fi networks ................................................................50
Using VPNs to protect connections to enterprise Wi-Fi networks............................................................52
Using enterprise captive portals to protect connections to enterprise Wi-Fi networks or Wi-Fi
hotspots ...............................................................................................................................................................52
Authenticating a BlackBerry device user ...........................................................................................................53
Authenticating a user to a BlackBerry device using a password...............................................................53
Authenticating a BlackBerry device user using a smart card.....................................................................53
Controlling BlackBerry devices............................................................................................................................55
© 2008 Research In Motion Limited. All rights reserved.
www.blackberry.com