Installation guide
BlackBerry Enterprise Solution 53
users must authenticate with the WLAN Login application browser using login credentials that the system
administrator provides.
When the BlackBerry device authenticates with the captive portal, the BlackBerry device user can use the
BlackBerry® Browser on the BlackBerry device to access other web sites and data service available on the
segregated Wi-Fi network. The BlackBerry device is designed to support web browsing using the BlackBerry MDS
Connection Service.
Authenticating a BlackBerry device user
When a user receives a new BlackBerry device, the BlackBerry Enterprise Solution uses either a desktop based or
wireless master encryption key generation method to authenticate the user and the BlackBerry device to the
BlackBerry Enterprise Server. The BlackBerry device user must have a valid email address for the BlackBerry
device to activate successfully and register with the wireless network.
Authenticating a user to a BlackBerry device using a password
When the BlackBerry Enterprise Server administrator adds a BlackBerry device to a BlackBerry Enterprise Server,
the BlackBerry Enterprise Server administrator can require a BlackBerry device user to authenticate to the
BlackBerry device using a security password. The BlackBerry Enterprise Server administrator can use IT policy
rules to set features such as password duration, length, and strength, to require password patterns, and to forbid
specific passwords. For more information, see the Policy Reference Guide.
If the BlackBerry device user intends to activate the BlackBerry device over the wireless network, they must
contact the BlackBerry Enterprise Server administrator for a temporary activation password that the BlackBerry
device uses to establish the master encryption key. The BlackBerry Enterprise Server administrator can set the
BlackBerry device activation password and communicate it to the BlackBerry device user.
The activation password
• applies to that BlackBerry device user’s email account only
• is not valid after five unsuccessful activation attempts
• expires if the BlackBerry device user does not activate the BlackBerry device within the default period of 48
hours, or a period of up to 720 hours that the BlackBerry Enterprise Server administrator sets after creating
the activation password
• is deleted from the BlackBerry Enterprise Server when the BlackBerry device activates successfully
Authenticating a BlackBerry device user using a smart card
Use two-factor authentication, using a smart card, to require BlackBerry device users to prove their identities to
their BlackBerry device using two factors:
• what they have (the smart card)
• what they know (their smart card password).
The BlackBerry Smart Card Reader integrates smart card use with the BlackBerry Enterprise Solution, enabling
BlackBerry device users to authenticate with their smart cards to login to certain Bluetooth enabled BlackBerry
devices.
The BlackBerry Smart Card Reader
• creates a reliable two-factor authentication environment for granting BlackBerry device users access to
BlackBerry and PKI applications
• is designed to enable the wireless digital signing and encryption of wireless email messages using the
S/MIME Support Package for BlackBerry devices
• stores all encryption keys in RAM only and never writes the keys to flash memory
www.blackberry.com