User guide
How a BlackBerry Enterprise Server and the BlackBerry Infrastructure authenticate with each other...................................89
What happens when a BlackBerry Enterprise Server and the BlackBerry Infrastructure open an initial connection ....... 90
How the BlackBerry Enterprise Solution protects a TCP/IP connection between a BlackBerry Enterprise Server
and the BlackBerry Infrastructure................................................................................................................................90
Data flow: Authenticating a BlackBerry Enterprise Server with the BlackBerry Infrastructure........................................ 91
How a BlackBerry Enterprise Server and messaging server protect a connection to each other ...........................................91
How the BlackBerry Enterprise Server components and the BlackBerry MVS protect communication .................................92
How the BlackBerry Desktop Manager protects communication using the BlackBerry inter-process protocol...................... 93
Data flow: Authenticating the application loader tool or Roxio Media Manager with the BlackBerry Desktop
Software using the BlackBerry inter-process protocol ..................................................................................................93
How the BlackBerry Collaboration Service connects to an instant messaging server and collaboration clients on devices .... 94
Protecting your organization’s resources when using BlackBerry MDS Connection Service integrated authentication.......... 94
Architecture: BlackBerry MDS Connection Service integrated authentication...............................................................95
How the BlackBerry MDS Connection Service uses Kerberos to help protect your organization's resources...................96
Identifying the resources that users can access using BlackBerry MDS Connection Service integrated
authentication.............................................................................................................................................................96
Data flow: Retrieving a resource when using BlackBerry MDS Connection Service integrated authentication.................96
Protecting your organization’s resources when you configure BlackBerry Administration Service single sign-on...................98
Architecture: BlackBerry Administration Service single sign-on....................................................................................98
How BlackBerry Administration Service single sign-on uses Kerberos to help protect your organization’s resources......99
How the BlackBerry Administration Service completes Kerberos authentication...........................................................99
Data flow: Accessing the BlackBerry Administration Service console and BlackBerry Web Desktop Manager when
you configure BlackBerry Administration Service single sign-on................................................................................. 100
12
Activating a device .......................................................................................................................102
Activating a device over the wireless network ...................................................................................................................102
Data flow: Activating a device over the wireless network ...................................................................................................103
13
Managing certificates on a device................................................................................................. 104
Purpose of certificates on a device................................................................................................................................... 104
Importing certificates onto a device..................................................................................................................................104
Configuring BlackBerry devices to enroll certificates over the wireless network..................................................................105
Managing an enrolled certificate...................................................................................................................................... 105
Determining the status of certificates using a CRL or OCSP...............................................................................................106
Data flow: Enrolling a certificate when the certification authority approves certificate requests automatically ....................107
Data flow: Enrolling a certificate when a certification authority administrator approves certificate requests .......................108
Data flow: Enrolling a certificate using an RSA certification authority.................................................................................109
14
Protecting BlackBerry Device Software updates ........................................................................... 111
Protecting BlackBerry Device Software updates over the wireless network........................................................................ 111
How the BlackBerry Enterprise Solution protects BlackBerry Device Software updates over the wireless network
using encryption
....................................................................................................................................................... 111
How the BlackBerry Enterprise Solution protects BlackBerry Device Software updates over the wireless network
using IT policies and content protection.....................................................................................................................112