
BlackBerry Enterprise Solution Security
Authenticating a user 34
HTTPS
protocol
BlackBerry MDS encryption method Description
proxy mode
TLS/SSL
Sun® JSSE 1.4.1 cipher suite
components
• The connection service sets up the proxy
mode TLS/SSL connection on behalf of the
BlackBerry device.
• The BlackBerry device does not use proxy
mode TLS/SSL to encrypt data traffic over the
wireless network; BlackBerry standard
encryption encrypts the data traffic between
the BlackBerry device and BlackBerry
Enterprise Server. Data traffic is therefore
encrypted over the wireless network unless it
is behind the corporate firewall.
• The BlackBerry device experiences faster
response times using this protocol than with
handheld mode TLS/SSL.
handheld mode
TLS/SSL
TLS and WTLS key establishment
algorithms, symmetric ciphers and
hash algorithms that the RIM Crypto
API currently supports on the
BlackBerry device
• The BlackBerry device uses handheld (direct)
mode TLS/SSL to encrypt data for the entire
connection between the BlackBerry device
and the content server.
• Data traffic over the wireless network remains
encrypted and is not decrypted at the
connection service.
• Use handheld mode TLS/SSL when only the
endpoints of the transaction are trusted (for
example, with banking services).
Note: BlackBerry devices with BlackBerry Device
Software version 3.6.1 or later support BlackBerry
device handheld mode TLS/SSL connections.
WAP gateway connections
BlackBerry Device Software version 3.2.1 or later supports WTLS, which is designed to provide an extra layer of
security when connecting to a WAP gateway. WTLS requires a WAP gateway to provide standard WAP access to
the Internet. To use a WAP gateway, your company must work with the network operator or service provider.
Authenticating a user
When a user receives a new BlackBerry device, the BlackBerry Enterprise Solution uses either a desktop-based or
wireless master encryption key generation method to authenticate the user and their BlackBerry device to the
BlackBerry Enterprise Server. The user must have a valid email address for their BlackBerry device to activate
successfully and register with the wireless network.
Authenticating a user to a BlackBerry device using a password
When you add a BlackBerry device to a BlackBerry Enterprise Server, you can require a user to authenticate to
the BlackBerry device using a security password. You can use IT policy rules to configure features such as
password duration, length, and strength, to require password patterns, and to forbid specific passwords. See the
Policy Reference Guide for more information.
www.blackberry.com
Comentarios a estos manuales