Specifications
For PEAP authentication, EAP-TLS authentication, or EAP-TTLS authentication to be successful, the device must trust the
certificate of the authentication server. The device does not trust the certificate of the authentication server automatically.
Before you can configure the device to trust the certificate of the authentication server, the following conditions must exist:
• A CA that the device and authentication server mutually trust must generate the certificate of the authentication server
and a certificate for the device.
• The device must store the root certificates in the certificate chain for the certificate of the authentication server.
Each device stores a list of root certificates that are issued by CAs that it explicitly trusts.
You can send root certificates to every device and you can use SCEP to enroll client certificates on devices. For more
information, see the BlackBerry Device Service Advanced Administration Guide.
Security Technical Overview How devices connect to the BlackBerry Device Service
29