Blackberry S-MIME SUPPORT PACKAGE VERSION 4.1 - Installationsanleitung Seite 35

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 52
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 34
BlackBerry Enterprise Solution Security
Authenticating a user 35
If the user intends to activate their BlackBerry device wirelessly, they must contact you for a temporary
activation password that the BlackBerry device uses to establish the master encryption key. You can set the
BlackBerry device activation password and communicate it to the user.
The activation password
applies to that user’s email account only
is not valid after five unsuccessful activation attempts
expires if a user does not activate the BlackBerry device within the default period of 48 hours, or a period of
up to 720 hours that you configure after you create their activation password
is removed from the BlackBerry Enterprise Server when the BlackBerry device activates successfully
Authenticating a user using a smart card
Use two-factor authentication, using a smart card, to require users to prove their identity to the BlackBerry
device by two factors:
what they have (the smart card)
what they know (their smart card password).
The BlackBerry Smart Card Reader integrates smart card use with the BlackBerry Enterprise Solution, enabling a
user to authenticate with their smart card to login to certain Bluetooth-enabled BlackBerry devices.
The BlackBerry Smart Card Reader
creates a reliable two-factor authentication environment for granting users access to BlackBerry and PKI
applications
is designed to enable the wireless digital signing and encryption of wireless email messages using the
S/MIME Support Package
stores all encryption keys in RAM only and never writes the keys to flash memory
See the BlackBerry Smart Card Reader Security White Paper for more information.
Binding the smart card to the BlackBerry device
If a user has a smart card authenticator, smart card driver, and smart card reader driver installed on their
BlackBerry device, either you or that user can initiate two-factor authentication on the BlackBerry device to bind
the BlackBerry device to the installed smart card. After the BlackBerry device binds to the smart card, it requires
that smart card to authenticate the user.
You can set the Force Smart Card Two-Factor Authentication IT policy rule in the BlackBerry Manager to require
that a user authenticates with the BlackBerry device using a smart card. If you do not force the user to
authenticate with the BlackBerry device using a smart card, the user can turn two-factor authentication on and
off with their smart card by setting the User Authenticator field in the BlackBerry device Security Options.
When you or the user enables two-factor authentication, the following events occur:
1. The BlackBerry device locks.
2. When a user tries to unlock the BlackBerry device, the BlackBerry device prompts the user to type the
BlackBerry device password. If the user has not yet set a BlackBerry device password, the BlackBerry device
forces them to set one.
3. The BlackBerry device prompts the user to type the user authenticator (smart card) password to turn on
two-factor authentication with the installed smart card.
4. The BlackBerry device binds to the installed smart card automatically by storing the following smart card
binding information in a special BlackBerry device NV store location that is inaccessible to a user:
name of a Java class required by the BlackBerry Smart Card Reader
www.blackberry.com
Seitenansicht 34
1 2 ... 30 31 32 33 34 35 36 37 38 39 40 ... 51 52

Kommentare zu diesen Handbüchern

Keine Kommentare