Force Smart Card Two Factor Challenge Response IT policy rule
Description
This rule specifies whether the user must choose a smart card certificate to use with smart card two-factor authentication.
This feature is designed to increase the security of smart card two-factor authentication, but when it is turned on, a BlackBerry®
device requires more time to unlock.
Default value
The default value is No.
Usage
If you change this rule to Yes, when the user unlocks a BlackBerry device, the BlackBerry device sends a challenge to the smart
card to verify the authenticator module for the smart card.
If you change this rule to Yes, to use a BlackBerry device, a user must have a BlackBerry® Smart Card Reader, and must install a
smart card driver and a BlackBerry Smart Card Reader driver on the BlackBerry device.
Dependencies
A BlackBerry device uses this rule only if you configure the Password Required and Force Smart Card Two Factor Authentication
IT policy rules to Yes.
Minimum requirements
•
Java® based BlackBerry device
•
BlackBerry® Connect™ version 4.0
•
BlackBerry® Device Software version 4.2
•
BlackBerry Smart Card Reader software version 1.5
•
BlackBerry® Enterprise Server version 4.0 SP6
Key Store Password Maximum Timeout IT policy rule
Description
This rule specifies the maximum number of minutes that can elapse before the timeout period expires for the cached key store
password and the BlackBerry® device prompts the user to type the password. The permitted range is 1 through 60 minutes.
Default value
The default value is 60 minutes.
Usage
The BlackBerry device key store is the database that stores the user's private keys. The key store uses a password to protect the
user's private keys. By default, the BlackBerry device caches the key store password to minimize the number of key store password
prompts.
Policy Reference Guide
Security policy group
196