
BlackBerry Enterprise Solution Security
Controlling BlackBerry devices 36
• format of the binding information (currently, a version byte with a value of 0)
• type of smart card (for the Common Access Card, this string is “GSA CAC”)
• name of a Java class required by the smart card code
• unique 64-bit identifier that the smart card provides
• smart card label that the smart card provides (for example, “GRAHAM.JOHN.1234567890”)
5. The BlackBerry device pushes the current IT policy to the BlackBerry Smart Card Reader.
Confirming that the BlackBerry device is bound to the correct smart card
After a user turns on two-factor authentication, whenever the BlackBerry device prompts the user to insert the
smart card into the BlackBerry Smart Card Reader, the BlackBerry device prompt indicates the label and the card
type of the correct (bound) smart card. If the BlackBerry device is running BlackBerry Device Software version
3.6 or earlier with either the S/MIME Support Package version 1.5 installed or no S/MIME Support Package
installed, the information in the prompt is the only indication that a smart card is bound to the BlackBerry device.
If the BlackBerry device is running either BlackBerry Device Software version 3.6 or earlier with the S/MIME
Support Package version 4.0 or later installed or BlackBerry Device Software version 4.0 or later (S/MIME
Support Package optional), the user can also view smart card information in the BlackBerry device Security
Options.
Field Description
Name indicates the type of the installed smart card
Initialized indicates whether the BlackBerry device is authenticated with and bound to the smart
card
• a value of Yes indicates that the BlackBerry device is bound to the smart card
• a value of No indicates that the BlackBerry device is not bound to the smart card
Controlling BlackBerry devices
With the BlackBerry Enterprise Solution, you can monitor and control all BlackBerry devices wirelessly from the
BlackBerry Manager.
Controlling BlackBerry device behaviour using IT policy rules
Use one or more IT policies to control the behavior of BlackBerry devices and the BlackBerry Desktop Software in
your organization.
The Default IT policy includes all standard IT policy rules on the BlackBerry Enterprise Server. When new users in
a BlackBerry Domain complete activation of their BlackBerry devices on the BlackBerry Enterprise Server, the
BlackBerry Enterprise Server automatically pushes the Default IT policy to their BlackBerry devices. The standard
IT policy rules do not enforce the default BlackBerry device or BlackBerry Desktop Software behavior. You can
use either of the following methods to change the default behavior of BlackBerry devices and BlackBerry
Desktop Software in your organization:
• set the values of IT policy rules in the Default IT policy
• create a new IT policy, set its IT policy rule values, and assign one or more users or user groups to the new IT
policy
Changing the default behavior
An IT policy rule enables you to customize and control BlackBerry device and BlackBerry Desktop Software
functionality using the following methods:
• setting a rule to a True or False value
www.blackberry.com
Comentarios a estos manuales