System information

37
4: Configuring your environment
Create Windows groups to support administrative roles
If you are using DB2 UDB, you cannot manage administrative roles using the BlackBerry Manager. You must
create Windows groups on the database server for each administrative role and then assign Windows users or
groups to those administrative role Windows groups.
> Perform the following actions:
Configure the local system account
for database authentication.
1. On the computer on which you plan to upgrade the BlackBerry Enterprise Server, open the
Registry Editor.
2. In the left pane, browse to HKEY_USERS\.DEFAULT.
3. Create the following nested keys (if they do not already exist):
•Software
•Research In Motion
BlackBerry Enterprise Server
•Database
4. Right-click Database, and then create the following string values:
Login: Type a database account that has the required database permissions.
Password: Type the password for the database account.
Action Procedure
Create a Windows group for each
administrative role on the database server.
1. On your database server, open the Microsoft Windows Computer Management
console.
2. Create the following Windows groups:
rim_db_admin_audit_enterprise
rim_db_admin_audit_handheld
rim_db_admin_audit_jr_helpdesk
rim_db_admin_audit_sr_helpdesk
rim_db_admin_enterprise
rim_db_admin_handheld
rim_db_admin_jr_helpdesk
rim_db_admin_sr_helpdesk
Assign Windows users or groups to each
administrative role Windows group.
> Use the Microsoft Windows Computer Management console to assign Windows users
or groups to each administrative role Windows group.
Visit www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/
c74f9f42-21b3-4786-9f20-39016fa19b51.mspx for more information about Windows
group management.
Warning: Do not assign users or groups to more than one administrative role’s Windows
group. If you do, the permissions of the highest role are applied.
Set the database server to authenticate
remote BlackBerry Managers.
> Use the IBM DB2 UDB Control Center to set the following settings:
control authentication at the client
•trust the client authenticating at the server
search locally for the administrative role Windows groups you created
Action Procedure