Specifications

To set up a TLS connection between the BlackBerry Device Service and a device so that the BlackBerry Device Service
can activate the device and send management commands to it
The BlackBerry Device Service setup application creates the server certificate during the installation process.
When a user activates a device, the device generates a key pair and sends the public key to the BlackBerry Device Service
in a CSR. The BlackBerry Device Service creates a client certificate and sends the enterprise management root certificate
and client certificate to the device. The BlackBerry Device Service and device automatically renew the client certificate
when it expires after one year.
The device uses the enterprise management root certificate to verify the server certificate for the Enterprise Management
Web Service. The BlackBerry Device Service and the device use the client certificate to authenticate the user, work space,
and device.
Related information
Data flow: Activating a device over a work Wi-Fi connection or a VPN connection, 31
Data flow: Activating a device over a connection to the BlackBerry Infrastructure, 33
Data flow: Activating a device using the BlackBerry Web Desktop Manager, 36
Using SCEP to enroll client certificates to a
device
SCEP is an IETF protocol that simplifies the process of enrolling certificates to a large number of users. Devices can
connect to any SCEP compliant CA, such as a Microsoft CA, using SCEP. The devices can use SCEP to connect to the CA
that is used by your organization and obtain any required client certificates.
You can use SCEP to enroll client certificates to devices so that the devices can connect to a work Wi-Fi network, work VPN
network, or work messaging server using Microsoft ActiveSync. Certificate enrollment starts after a device receives a Wi-Fi
profile, VPN profile, or email profile that has an associated SCEP profile that you configured using the BlackBerry Device
Service. Devices can receive a SCEP profile from the BlackBerry Device Service during the activation process, when you
change a SCEP profile, or when you change another profile that has an associated SCEP profile. After the certificate
enrollment completes, the client certificate and its certificate chain and private key are stored in the work keystore on the
device.
The CA that you use must support challenge passwords. You set the challenge password in the SCEP profile. All devices
that use the SCEP profile use the same challenge password. To help protect this password, the password is not sent to the
devices.
For more information about SCEP, visit www.ietf.org.
Managing certificates that a device enrolls using SCEP
After a device enrolls a certificate using SCEP, the SCEP component monitors the expiry date and revocation status of the
certificate. When the expiry date of a certificate approaches, the SCEP component starts the enrollment process for a new
Security Technical Overview Managing certificates on devices
39