Blackberry Pearl 8100 Series User Manual Supplement
Blackberry Pearl 8100 Series User Manual Supplement

Blackberry Pearl 8100 Series User Manual Supplement

S/mime support package for blackberry smartphones
Hide thumbs Also See for Pearl 8100 Series:

Advertisement

User Guide Supplement
S/MIME Support Package for BlackBerry Smartphones
BlackBerry Pearl 8100 Series

Advertisement

Table of Contents
loading

Summary of Contents for Blackberry Pearl 8100 Series

  • Page 1 User Guide Supplement S/MIME Support Package for BlackBerry Smartphones BlackBerry Pearl 8100 Series...
  • Page 2 SWD-292878-0324093908-001...
  • Page 3: Table Of Contents

    Contents Certificates...3 Certificate basics...3 Certificate status...5 Certificate options...7 Certificate shortcuts...8 Certificate troubleshooting...9 Certificate servers...11 Add a certificate server...11 Change connection information for a certificate server...11 Connection options for LDAP certificate servers...11 Connection options for OCSP and CRL servers... 12 Send connection information for a certificate server ... 12 Delete a certificate server...
  • Page 5: Certificates

    This field displays the trust status of the certificate chain. A certificate can be explicitly trusted (the certificate itself is trusted), implicitly trusted (the root certificate in the certificate chain is trusted on your BlackBerry® device), or not trusted (the certificate is not explicitly trusted and the root certificate in the certificate chain is not trusted or does not exist on your device).
  • Page 6 To view all the certificates on your BlackBerry® device, press the Menu key. Click Show All Certs. Send a certificate When you send a certificate, your BlackBerry® device sends the public key, but does not send the corresponding private key. 1. In the device options, click Security Options.
  • Page 7: Certificate Status

    Certificate status Certificate status indicators The certificate has a corresponding private key that is stored on your BlackBerry® device or a smart card. The certificate chain is trusted and valid, and the revocation status of the certificate chain is good.
  • Page 8 • To trust the highlighted certificate and all the other certificates in the chain, click Entire Chain. Revoke a certificate If you revoke a certificate, the certificate is revoked only in the key store on your BlackBerry® device. Your device does not update the revocation status on the certificate authority or CRL servers.
  • Page 9: Certificate Options

    Superseded: A new certificate is replacing an existing certificate. Cessation of Operation: The certificate subject no longer requires the certificate. Certificate Hold: You want to revoke the certificate temporarily. Certificate options Change the display name for a certificate 1. In the device options, click Security Options. 2.
  • Page 10: Certificate Shortcuts

    8. Press the Menu key. 9. Click Save. When you add a certificate, your BlackBerry® device uses the certificate subject as the name for the certificate. Turn off the fetch status prompt that appears when you add a certificate to the key store 1.
  • Page 11: Certificate Troubleshooting

    Certificate troubleshooting I cannot download a certificate If you changed the connection type that your BlackBerry® device uses to connect to the LDAP certificate server, try switching to the default connection type.
  • Page 13: Certificate Servers

    Certificate servers Add a certificate server 1. In the device options, click Security Options. 2. Click Certificate Servers. 3. Press the Menu key. 4. Click New Server. 5. Specify information for the certificate server. 6. Press the Menu key. 7. Click Save. Change connection information for a certificate server 1.
  • Page 14: Connection Options For Ocsp And Crl Servers

    Connection Type: Specify whether your BlackBerry® device uses an SSL connection or a TLS connection to connect to the certificate server. Connection options for OCSP and CRL servers Friendly Name: Type a display name for the certificate server. Server URL: Type the web address of the certificate server.
  • Page 15: Key Stores

    Key stores About the key store The key store on your BlackBerry® device might store the following items. To access these items in the key store, you must type a key store password. • personal certificates (certificate and private key pairs) •...
  • Page 16: Change The Service That Your Device Uses To Download Certificates

    Turn off automatic backup of key store data By default, items in the key store on your BlackBerry® device are backed up or restored when you back up or restore your device data. If you do not want to back up your private key to or restore your private key from your computer for security reasons, you can turn off automatic backup and restore of key store data.
  • Page 17 2. Click Key Stores. 3. Change the Accept Unverified CRLs field to No. 4. Press the Menu key. 5. Click Save. Your BlackBerry® device rejects certificate revocation lists from CRL servers that the BlackBerry® MDS Connection Service cannot verify.
  • Page 19: S/Mime-Protected Messages

    5. Click Continue. Download the certificate used to sign or encrypt a message If a certificate is not included in a received message or is not already stored in the key store on your BlackBerry® device, you can download the certificate.
  • Page 20 Add a certificate from a message 1. In a message, highlight a digital signature indicator. 2. Press the Menu key. 3. Click Import Sender’s certificate. Add a certificate from an attachment 1. In a message, click the certificate attachment. 2. Click Retrieve Certificate Attachment. 3.
  • Page 21: S/Mime-Protected Message Status

    Check the status of a certificate or certificate chain If a certificate is included in a received message, or is already stored in the key store on your BlackBerry® device, you can check the status of the sender's certificate, or you can check the status of the sender's certificate and all other certificates in the certificate chain.
  • Page 22: S/Mime-Protected Message Options

    Change the default signing and encryption option Your BlackBerry® device is designed to use the default signing and encryption option when you send a message to a contact that you have not sent a message to or received a message from previously. If you have sent a message to or received message from the contact previously, your device tries to use the signing and encryption option that was used for the last message.
  • Page 23: Change The Default Message Classification

    Verify that your administrator has turned on message classifications. Your BlackBerry® device is designed to use the default message classification when you send a message to a contact that you have not sent a message to or received a message from previously. If you have sent a message to or received message from the contact previously, your device tries to use the message classification that was used for the last message.
  • Page 24: S/Mime-Protected Message Troubleshooting

    I cannot open an attachment in an encrypted message The attachment information might not be available on the BlackBerry® Enterprise Server, your administrator might have set options to prevent you from opening attachments in encrypted messages, or you might have received the message from an email account that does not support attachments in encrypted messages.
  • Page 25: Smart Cards

    Smart cards store certificates and private keys. You can use a smart card reader to import certificates from a smart card to the key store on your BlackBerry® device, but you cannot import private keys. As a result, private key operations such as signing and decryption use the smart card, and public key operations such as verification and encryption use the public certificates on your device.

Table of Contents