background image

VPN Password Hidden on Input IT policy rule

Description

This rule specifies whether a BlackBerry® device displays asterisks (*) instead of characters when the user types the VPN password.

Default value

The default value is No.

Usage

Change this rule to Yes to hide the VPN password as the user types it.

Minimum requirements

Java® based BlackBerry device

BlackBerry® Device Software version 4.2.1

BlackBerry® Enterprise Server version 4.1 SP3

VPN PFS IT policy rule

Description

This rule specifies whether Perfect Forward Secrecy is turned on for a BlackBerry® device.

Default value

The default value is Yes.

Usage

Change the value only if your organization does not support Perfect Forward Secrecy.

Minimum requirements

Java® based BlackBerry device

BlackBerry® Device Software version 4.0

BlackBerry® Enterprise Server version 4.0 SP1

VPN Primary DNS IT policy rule

Description

This rule specifies the static setting for the IP address of your organization's primary DNS server.

Default value

The default value is a null value.

Dependencies

Policy Reference Guide

VPN policy group

249

Содержание Enterprise Server 5.0 sp2

Страница 1: ...BlackBerry Enterprise Server Version 5 0 Service Pack 2 Policy Reference Guide...

Страница 2: ...Published 2010 06 16 SWDT323212 1063796 0616124539 001...

Страница 3: ...Force Load Message IT policy rule 29 Forward Messages In Cradle IT policy rule 30 Message Conflict Mailbox Wins IT policy rule 30 Message Prompt IT policy rule 31 Show Application Loader IT policy rul...

Страница 4: ...on List IT policy rule 48 Disable Application Purchasing IT policy rule 48 Enable Wireless Service Provider Billing IT policy rule 49 BlackBerry Messenger policy group 49 Disable BlackBerry Messenger...

Страница 5: ...raffic Inactivity Timeout IT policy rule 62 Maximum PC Disconnected Timeout IT policy rule 62 Maximum PC Long Term Timeout IT policy rule 63 Maximum Smart Card Not Present Timeout IT policy rule 64 Mi...

Страница 6: ...in Browser IT policy rule 76 Disable JavaScript in Browser IT policy rule 77 Download Images URL IT policy rule 77 Download Themes URL IT policy rule 78 Download Tunes URL IT policy rule 78 MDS Browse...

Страница 7: ...policy group 91 Allow Chalk Pushcast Player Auto Update Prompt IT policy rule 91 Allow Chalk Pushcast Player Roaming IT policy rule 91 Allow Launch of Chalk Pushcast Player IT policy rule 92 Chalk Pu...

Страница 8: ...ynchronization IT policy rule 106 Force updates for application loader tool IT policy rule 107 Generate Encrypted Backup Files IT policy rule 107 Override Check For Updates URL IT policy rule 107 Devi...

Страница 9: ...olicy rule 119 External Display policy group 120 Display Notification Details IT policy rule 120 Include Message Text in Notification Details IT policy rule 120 Firewall policy group 121 Restrict Inco...

Страница 10: ...licy rule 132 Memory Cleaner policy group 132 Force Memory Clean When Closed IT policy rule 132 Force Memory Clean When Holstered IT policy rule 133 Force Memory Clean When Idle IT policy rule 133 Mem...

Страница 11: ...thod IT policy rule 150 PGP Universal Policy Cache Timeout IT policy rule 151 PGP Universal Server Address IT policy rule 151 Phone policy group 152 Outgoing Call Redirection IT policy rule 152 RIM Va...

Страница 12: ...al Connections IT policy rule 164 Allow Outgoing Call When Locked IT policy rule 164 Allow Resetting of Idle Timer IT policy rule 165 Allow Screen Shot Capture IT policy rule 165 Allow Smart Card Pass...

Страница 13: ...tificate Status Checks IT policy rule 183 Disable Stale Status Use IT policy rule 183 Disable Untrusted Certificate Use IT policy rule 184 Disable Unverified Certificate Use IT policy rule 184 Disable...

Страница 14: ...ng Key Store Security Level IT policy rule 201 Password Required for Application Download IT policy rule 201 Require Secure APB Messages IT policy rule 202 Required Password Pattern IT policy rule 202...

Страница 15: ...18 Allow Public WLM Services IT policy rule 218 Allow Public Yahoo Messenger Services IT policy rule 218 Allow Network Address Book Sync IT policy rule 219 SIM Application Toolkit policy group 219 Dis...

Страница 16: ...ity IT policy rule 232 Require Password IT policy rule 232 VoIP policy group 233 Allow VoIP IT policy rule 233 Disable VoIP User Profiles IT policy rule 233 SIP Authentication ID IT policy rule 234 SI...

Страница 17: ...policy rule 247 VPN IPSec Cipher and Hash IT policy rule 247 VPN Minimal Certificate Encryption Key Security Level IT policy rule 248 VPN NAT Keep Alive IT policy rule 248 VPN Password Hidden on Input...

Страница 18: ...Encryption Key Security Level IT policy rule 262 Wi Fi Password Hidden on Input IT policy rule 262 Wi Fi Preshared Key IT policy rule 263 Wi Fi Primary DNS IT policy rule 263 Wi Fi Profile Forwarding...

Страница 19: ...configuration setting 278 SIP Authentication ID configuration setting 278 SIP Domain configuration setting 279 SIP Local Port configuration setting 279 SIP Realm configuration setting 279 SIP Registr...

Страница 20: ...PSec Cipher and Hash configuration setting 293 VPN Minimal Certificate Encryption Key Security Level configuration setting 293 VPN NAT Keep Alive configuration setting 294 VPN PFS configuration settin...

Страница 21: ...i Fi Link Security configuration setting 306 Wi Fi Minimal EAP TLS Certificate Encryption Key Security Level configuration setting 307 Wi Fi Preshared Key configuration setting 307 Wi Fi Primary DNS c...

Страница 22: ...be Modified application control policy rule 322 Is Access to the File API Allowed application control policy rule 322 Is Access to the Media API Allowed application control policy rule 322 Is Access t...

Страница 23: ...ng user control of third party applications on BlackBerry devices 332 Preventing RIM value added applications from running on BlackBerry devices 332 6 Glossary 334 7 Provide feedback 340 8 Legal notic...

Страница 24: ...on might not For more information contact your organization s device supplier Devices that are running the BlackBerry Application Suite can use all the IT policy rules that are associated with the sup...

Страница 25: ...otheAdvancedSecurityITpolicy thisITpolicyrequiresacomplexpassword that a user must change frequently a password timeout that locks the BlackBerry device and a maximum password history This policy rest...

Страница 26: ...alue Added Applications Deactivate eBay for BlackBerry smartphones RIM Value Added Applications Disable Feeds application 6 0 RIM Value Added Applications Enable the Tell A Friend Feature in BlackBerr...

Страница 27: ...0 BlackBerry Desktop Software version 3 5 or BlackBerry Web Desktop Manager version 1 0 BlackBerry Enterprise Server version 3 5 for Microsoft Exchange BlackBerry Enterprise Server version 4 0 for IB...

Страница 28: ...st configure the Auto Backup Include All IT policy rule to No Minimum requirements BlackBerry Application Suite version 1 0 BlackBerry Desktop Software version 3 5 or BlackBerry Web Desktop Manager ve...

Страница 29: ...nd restore tool options the Backup all device application data option is selected If you configure the Auto Backup Exclude Sync or Auto Backup Exclude Messages IT policy rules to Yes change this rule...

Страница 30: ...value is No The BlackBerry device saves a copy of each email message that a user sends Usage Change this rule to Yes to prevent the storage of email messages that a user sends from a BlackBerry devic...

Страница 31: ...Wise Exceptions The BlackBerry Enterprise Server for Novell GroupWise supports this rule with the BlackBerry Web Desktop Manager only Force Load Message IT policy rule Description This rule specifies...

Страница 32: ...t Exchange or BlackBerry Enterprise Server version 4 0 for IBM Lotus Domino Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Message Conflict Mailbox Wins IT...

Страница 33: ...in the BlackBerry Desktop Manager and the BlackBerry Web Desktop Manager Default value The default value is Yes Usage Change this rule to No to hide the Device Software tab in the BlackBerry Web Deskt...

Страница 34: ...ersion 4 0 for IBM Lotus Domino Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Synchronize Messages Instead Of Importing IT policy rule Description This ru...

Страница 35: ...erry Enterprise Server version 4 0 for IBM Lotus Domino Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Web Link URL IT policy rule Description This rule sp...

Страница 36: ...versions 1 2 2 0 2 1 or 4 0 BlackBerry Enterprise Server version 3 5 for Microsoft Exchange BlackBerry Enterprise Server version 4 0 for IBM Lotus Domino or BlackBerry Enterprise Server version 4 0 f...

Страница 37: ...rry Device Software version 4 0 or later Allow SMS IT policy rule Description This rule specifies whether a user can send SMS text messages Default value The default value is Yes Usage Change this rul...

Страница 38: ...Novell GroupWise supports this rule in BlackBerry Device Software version 4 0 or later Enable Long Term Timeout IT policy rule Description This rule specifies whether a BlackBerry device locks after...

Страница 39: ...er uses the WAP service for MMS messaging Minimum requirements Java based BlackBerry device BlackBerry Connect versions 2 1 4 0 BlackBerry Device Software version 3 6 BlackBerry Enterprise Server vers...

Страница 40: ...nts C based BlackBerry device that is running BlackBerry Device Software version 2 5 Java based BlackBerry device that is running BlackBerry Device Software version 3 6 BlackBerry Application Suite ve...

Страница 41: ...m Security Timeout IT policy rule Description This rule specifies the maximum time in minutes that a BlackBerry device user can specify as the security timeout value The security timeout value is the...

Страница 42: ...5 Java based BlackBerry device that is running BlackBerry Device Software version 3 6 BlackBerry Application Suite version 1 0 BlackBerry Connect versions 1 2 2 0 2 1 or 4 0 BlackBerry Enterprise Serv...

Страница 43: ...ng BlackBerry Device Software version 2 5 Java based BlackBerry device that is running BlackBerry Device Software version 3 6 BlackBerry Application Suite version 1 0 BlackBerry Connect version 1 2 2...

Страница 44: ...onnect versions 1 2 2 0 2 1 4 0 BlackBerry Device Software version 3 6 BlackBerry Enterprise Server version 3 5 for Microsoft Exchange BlackBerry Enterprise Server version 4 0 for IBM Lotus Domino or...

Страница 45: ...he BlackBerry Browser is available on a BlackBerry device Default value The default value is Yes Usage This rule does not affect other browsers such as the WAP browser For more information about the b...

Страница 46: ...BlackBerry Enterprise Server version 4 0 for Novell GroupWise Exceptions The BlackBerry Enterprise Server for Novell GroupWise supports this rule in BlackBerry Device Software version 4 0 or later Au...

Страница 47: ...evice user from accessing the application center Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 3 BlackBerry Enterprise Server version 4 1 SP6 Disable Carrier D...

Страница 48: ...le replaces the Disable BlackBerry App World IT policy rule in the Security policy group Minimum requirements Java based BlackBerry device BlackBerry Device Software 4 5 BlackBerry Enterprise Server 5...

Страница 49: ...ebstore and click Get Details for the application The application ID is the number that is located at the end of the URL for the application Dependencies You must configure the Application Restriction...

Страница 50: ...or example if you want to prevent a user from purchasing and downloading applications from the Entertainment Games and Shopping categories type 7 1 45 Default values The default value is a null value...

Страница 51: ...ice provider Default values The default value is No A user cannot purchase applications from BlackBerry App World using the purchasing plan for your organization s wireless service provider Usage If y...

Страница 52: ...ers of BlackBerry Messenger groups send to each other You can prevent users from participating in BlackBerry Messenger groups if your organization s security policies require you to audit all informat...

Страница 53: ...ontact list for the BlackBerry Messenger in the BlackBerry Infrastructure Default value The default value is No A BlackBerry device user can store a contact list in the BlackBerry Infrastructure Usage...

Страница 54: ...Device Software version 4 6 BlackBerry Enterprise Server version 4 1 SP6 Disallow Setting a Subject on Conversations IT policy rule Description This rule specifies whether a BlackBerry device user ca...

Страница 55: ...ages in a report the report includes the date that a user sent the messages The date is the time on the device converted into UTC time Minimum requirements Java based BlackBerry device BlackBerry Appl...

Страница 56: ...rted into UTC time Minimum requirements Java based BlackBerry device BlackBerry Application Suite 1 0 BlackBerry Device Software 3 6 BlackBerry Enterprise Server 4 0 SP2 Messenger Audit UID IT policy...

Страница 57: ...connect On BlackBerry option to prevent a BlackBerry device from reconnecting automatically to a BlackBerry Smart Card Reader Select the Disable Auto Reconnect On PC option to prevent a computer from...

Страница 58: ...r If you change this rule to Yes the user cannot turn off this feature on the computer Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Se...

Страница 59: ...onnection between a BlackBerry device and a BlackBerry Smart Card Reader closes that the disconnected timeout expires The permitted range is 0 through 604 800 seconds Default value The default value i...

Страница 60: ...imeout IT policy rule Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP2 BlackBerry Smart Card Reader software versio...

Страница 61: ...er software version 1 0 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Maximum Connection Heartbeat Period IT policy rule Description This rule specifies t...

Страница 62: ...ion 4 0 SP2 BlackBerry Smart Card Reader software version 1 0 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Maximum Number of BlackBerry Transactions IT p...

Страница 63: ...mart Card Reader software version 1 5 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Maximum Number of PC Transactions IT policy rule Description Thisrules...

Страница 64: ...lt value The default value is a null value The secure pairing information is not deleted from the computer Usage If you configure this rule the user cannot turn off this feature but can change the Ina...

Страница 65: ...rd Reader establish secure pairing information before the computer and BlackBerry Smart Card Reader delete the secure pairing information The permitted range is 1 through 720 hours Default value The d...

Страница 66: ...Enterprise Server version 4 0 SP2 BlackBerry Smart Card Reader software version 1 5 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule Minimum PIN Entry Mode...

Страница 67: ...rsion 4 2 2 BlackBerry Enterprise Server version 4 1 SP6 Disable Unite Applications IT policy rule Description This rule specifies whether to prevent applications for the BlackBerry Unite software fro...

Страница 68: ...a with a supported Bluetooth enabled device Default values The default value in the Advanced security and Advanced Security with No 3rd Party Applications IT policies is Yes A BlackBerry device cannot...

Страница 69: ...lt value is No Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 2 BlackBerry Enterprise Server version 4 1 SP4 Disable Bluetooth IT policy rule Description This...

Страница 70: ...Up Networking IT policy rule Description This rule specifies whether to prevent a BlackBerry device from using the Bluetooth DUN profile Default value The default value is No Minimum requirements Jav...

Страница 71: ...IT policies is No Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Disable Handsfree Profile IT policy rule Descrip...

Страница 72: ...example a headset that uses MAP can retrieve email messages and SMS text messages from or upload email messages and SMS text messages to a Bluetooth enabled BlackBerry device Default value The default...

Страница 73: ...pportsthisruleinBlackBerryDeviceSoftwareversion4 0andlater Disable Serial Port Profile IT policy rule Description This rule specifies whether a BlackBerry device can use the Bluetooth SPP Default valu...

Страница 74: ...6 Disable Wireless Bypass IT policy rule Description This rule specifies whether a BlackBerry device can use wireless bypass using Bluetooth technology Default value The default value is Yes Minimum r...

Страница 75: ...ckBerry device uses this rule only if you configure the Disable Discovery Mode IT policy rule to No Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 5 BlackBerry...

Страница 76: ...e Default values The default value in the Advanced security and Advanced Security with No 3rd Party Applications IT policies is Yes The default value in all other preconfigured IT policies is No Minim...

Страница 77: ...version 4 0 SP3 Browser policy group The rules in the Browser policy group apply to all browser configurations on the BlackBerry device Allow Application Download Services IT policy rule Description...

Страница 78: ...prise Server version 4 1 SP6 Allow IBS Browser IT policy rule Description This rule specifies whether a BlackBerry Internet Service Browsing icon appears on a BlackBerry device if the appropriate serv...

Страница 79: ...ript code on a BlackBerry device Default value The default value is No Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Connect version 4 0 interna...

Страница 80: ...es for a BlackBerry device Default value The default value is a null value Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version...

Страница 81: ...fix the domain with a period For example type yahoo ca to permit the BlackBerry Browser to retrieve all sub domains of yahoo ca such as mail yahoo ca www yahoo ca Minimum requirements Java based Black...

Страница 82: ...rry Enterprise Server version 4 0 SP2 MDS Browser Style Sheets Enabled IT policy rule Description This rule specifies whether style sheets in the BlackBerry Browser are turned on Default value The def...

Страница 83: ...appears on the Home screen of the BlackBerry device Default value The default value is No Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device...

Страница 84: ...was Certificate Authority Profile policy group Allow Private Key Export IT policy rule Description This rule specifies whether to prevent a user from exporting private keys that are included in the c...

Страница 85: ...nitial certificate enrollment process does not complete a BlackBerry device uses this rule to specify a retry time for the enrollment process Minimum requirements Java based BlackBerry device BlackBer...

Страница 86: ...MDSConnectionServicecanusetoconnecttothecertificationauthority The permitted range is 0 through 65535 The previous name of this rule was Certificate Authority Port Default value The default value is 8...

Страница 87: ...starts the certificate enrollment process automatically after the BlackBerry Enterprise Server pushes the IT policy to the BlackBerry device The user can cancel the enrollment process when the BlackBe...

Страница 88: ...user name from the email address to the common name but not the at sign or domain information Dependency If you change the Certification Authority Type rule to Microsoft Enterprise certification auth...

Страница 89: ...tinguished name of the certificate for example C Country O Organization OU Organizational Unit Default value The default value is a null value Usage A BlackBerry device accepts certificates only if th...

Страница 90: ...of 64 If you change the Key Algorithm rule to DSA you must configure the key size to be 512 768 or 1024 bits If you configure an unsupported key size a BlackBerry device chooses the next strongest ke...

Страница 91: ...te ID Default value The default value is a null value Usage You must map this value to the MD5 certificate ID for example 2094a3d152b66fb45ea69501970511f9 that the administrator of the RSA certificati...

Страница 92: ...iption This rule specifies a web address that produces random data for example a web site for a white noise machine If the S MIME Support Package for BlackBerry Smartphones version 4 0 or later is ins...

Страница 93: ...ue The default value is Yes Usage Change this rule to No if you do not want the Chalk Pushcast Player to prompt the user when an update is available Minimum requirements Java based BlackBerry device B...

Страница 94: ...ackBerry device BlackBerry Enterprise Server 5 0 SP2 Chalk Pushcast Player Default Connection Type IT policy rule Description This rule specifies the default connection type that the Chalk Pushcast Pl...

Страница 95: ...from the Chalk Pushcast Software over the wireless network in a one month period Default value The default value is 1 The data limit is unlimited Usage Change the value to 0 to prevent the Chalk Pushc...

Страница 96: ...re over the mobile network Change the value of this rule to Only use Wi Fi to permit only Wi Fi enabled BlackBerry devices to download content from the Chalk Pushcast Software and to permit the Wi Fi...

Страница 97: ...ckBerry Device Software version 4 0 BlackBerry Connect version 4 0 BlackBerry Enterprise Server version 4 0 and earlier Confirm On Send IT policy rule Description This rule specifies whether users mus...

Страница 98: ...ng and receiving MMS messages For more information see the BlackBerry Enterprise Solution Security Technical Overview Dependencies To block incoming MMS messages in the Security policy group configure...

Страница 99: ...er version 4 1 SP5 Enable Simultaneous Phone and Data IT policy rule Description This rule specifies whether a BlackBerry device user can send and receive data during a phone call Default value The de...

Страница 100: ...erry device You can lock the Information field the Name field or both fields Default value The default value is a null value Usage Configure this rule to Lock Information text that is defined using th...

Страница 101: ...Dependencies The Set Owner Info IT policy rule is related to the Lock Owner Info IT policy rule Minimum requirements C based BlackBerry device that is running BlackBerry Device Software version 2 7 J...

Страница 102: ...BlackBerry device including the synchronization of time zone information Automatic Time Zone Change Detection IT policy rule Description This rule specifies whether a BlackBerry device can update the...

Страница 103: ...whether a BlackBerry device can automatically synchronize its real time clock with a time source on the wireless network Default value The default value is Yes A BlackBerry device can synchronize its...

Страница 104: ...5 0 BlackBerry Enterprise Server version 5 0 SP1 Desktop policy group Allow BlackBerry Desktop Software Statistics IT policy rule Description This rule specifies whether the BlackBerry Desktop Softwa...

Страница 105: ...ication IT policy rule Description This rule specifies whether a BlackBerry device user can use the integrated IP modem application in the BlackBerry Desktop Manager Default value The default value is...

Страница 106: ...ckBerry Desktop Software can run add in applications such as third party COM based extensions that access BlackBerry device databases during synchronization Default value The default value is Yes Mini...

Страница 107: ...Berry Web Desktop Manager caches the BlackBerry device password in memory The permitted range is 0 through 720 minutes Default value The default value is 10 minutes Usage If you change this rule to 0...

Страница 108: ...using the media manager tool Minimum requirements BlackBerry Connect version 4 0 internal BlackBerry Desktop Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Exceptions The BlackBerr...

Страница 109: ...he user must update it manually Minimum requirements BlackBerry Desktop Software 5 0 SP1 BlackBerry Enterprise Server 5 0 SP2 Generate Encrypted Backup Files IT policy rule Description This rule speci...

Страница 110: ...BlackBerry device BlackBerry Device Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Set Diagnostic Report Email Address IT policy rule Description This rule specifies one or more em...

Страница 111: ...lackBerry device BlackBerry Device Software version 4 5 with the DataViz Documents to Go application installed BlackBerry Enterprise Server version 4 1 SP5 Hide Documents To Go Communication Menus IT...

Страница 112: ...Email Messaging policy group The rules in the Email Messaging policy group apply to wireless message reconciliation and attachment viewing Allow Auto Attachment Download IT policy rule Description Th...

Страница 113: ...kBerry Application Suite version 1 0 BlackBerry Connect version 4 0 BlackBerry Device Software version 4 2 for messages and version 5 0 for calendar entries BlackBerry Enterprise Server version 3 5 fo...

Страница 114: ...an send email messages that include embedded forms Default value The default value is No Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 5 BlackBerry Enterprise...

Страница 115: ...forward or reply to IBM Lotus Domino encrypted email messages that were received decrypted and decompressed on the BlackBerry device Usage If you change this rule to Yes a BlackBerry device user canno...

Страница 116: ...r version 3 5 for Microsoft Exchange BlackBerry Enterprise Server version 4 0 for IBM Lotus Domino or BlackBerry Enterprise Server version 4 0 for Novell GroupWise Exceptions The BlackBerry Enterprise...

Страница 117: ...umtime indays thataBlackBerry devicekeepssavedmessages Thepermittedrangeis 1through 180 days Default value The default value is 1 A BlackBerry device keeps messages indefinitely Usage Configure this r...

Страница 118: ...interacts with the Maximum Upload Attachment Size field in the BlackBerry Manager If you configure the fields the BlackBerry Enterprise Server sends the values to the device using service books The de...

Страница 119: ...res the IBM Lotus Notes id password that a user types The permitted range is 1 through 32 767 Default value The default value is 1 which indefinitely stores the password that the user types Usage Chan...

Страница 120: ...Change this rule to Yes to permit a user to send messages using IBM Lotus Notes encryption If necessary the BlackBerry device prompts a user for the IBM Lotus Notes encryption passwords A BlackBerry...

Страница 121: ...ersion 4 1 SP4 Disable Enterprise Voice Client IT policy rule Description This rule specifies whether enterprise voice is available on a BlackBerry device Default value The default value is No Minimum...

Страница 122: ...display of BlackBerry Pearl 8220 and BlackBerry 8210 smartphones Default value The default value is Always Usage Change this rule to Never to never display notification messages on the external displa...

Страница 123: ...lue Usage Type one or more fixed dialing patterns for example specific dialing numbers or a set of dialing numbers that have the same prefix separated by a semi colon To receive calls to numbers that...

Страница 124: ...ded by the number one or a plus sign and the number one only type 1 1 r To prevent calls that use a specific pattern append r to the pattern For example type 011 r to prevent calls that use the format...

Страница 125: ...er can permit collaboration clients that were previously logged into a BlackBerry device to log back in automatically after the BlackBerry device restarts or enters a wireless coverage area again Defa...

Страница 126: ...ticons and allows a user to add emoticons to conversations Default value The default value is No The collaboration client on a BlackBerry device displays emoticons and makes them available in conversa...

Страница 127: ...re version 4 2 BlackBerry Enterprise Server version 4 1 SP6 Disallow File Transfer Types IT policy rule Description This rule specifies the types of files that a BlackBerry device user cannot send usi...

Страница 128: ...cation Service IT policy rule Description ThisrulespecifieswhetheraBlackBerry devicecanusethegeolocationservicetoidentifythegeographiclocationofaBlackBerry device user Default value The default value...

Страница 129: ...device user to require that a BlackBerry device report its location to the BlackBerry Enterprise Server at regular intervals You can use the Enterprise Location Tracking Interval IT policy rule to ch...

Страница 130: ...icy group Allow Access to Multiple Domains IT policy rule Description This rule specifies whether to permit users to install a BlackBerry MDS Runtime Application that uses multiple web services on a B...

Страница 131: ...4 0 SP6 and later The default value is No Minimum requirements Java based BlackBerry device BlackBerry Application Suite 1 0 BlackBerry Device Software 4 2 BlackBerry Enterprise Server 4 1 SP2 Disabl...

Страница 132: ...y Enterprise Server version 4 0 SP6 Enable Access to Device Data for MDS Runtime 4 3 0 and earlier IT policy rule Description This rule specifies whether BlackBerry MDS Runtime version 4 3 0 and earli...

Страница 133: ...ion This rule specifies the maximum number of incoming messages from BlackBerry MDS Runtime that can be queued locally on a BlackBerry device The permitted range is 0 through 1000 messages Default val...

Страница 134: ...a based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Memory Cleaner policy group For more information...

Страница 135: ...does not support this rule Force Memory Clean When Idle IT policy rule Description This rule specifies whether a BlackBerry device cleans its memory during periods of user inactivity Default value The...

Страница 136: ...lackBerry Device Software version 3 6 BlackBerry Enterprise Server version 4 0 SP3 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule On Device Help policy gro...

Страница 137: ...ed IT policy rule to Yes For more information about using passwords on BlackBerry devices see the BlackBerry Enterprise Solution Security Technical Overview Duress Notification Address IT policy rule...

Страница 138: ...ue The default value is a null value Usage By default a BlackBerry device prevents a user from configuring passwords that use a natural sequence of characters or numbers The BlackBerry device also aut...

Страница 139: ...kBerry device locks and prompts a user to type a password regardless of whether the BlackBerry device was active during that interval Default value By default if you change the Enable Long Term Timeou...

Страница 140: ...priseServerforNovell GroupWise supportsthisruleinBlackBerryDeviceSoftwareversions4 0andlater Set Password Timeout IT policy rule Description This rule specifies the number of minutes of inactivity bef...

Страница 141: ...Dependencies The BlackBerry device uses this rule only if a password is configured on the BlackBerry device To require a password configure the Password Required rule to Yes To specify the number of...

Страница 142: ...eless Synchronization IT policy rule Description This rule specifies whether wireless data synchronization is turned off Default value The default value is No Usage Change this rule to Yes to turn off...

Страница 143: ...e database for the BlackBerry Messenger is turned off Default value The default value is Yes The message database for the BlackBerry Messenger does not synchronize wirelessly Usage When you change thi...

Страница 144: ...ation Suite 1 0 BlackBerry Device Software 4 2 BlackBerry Enterprise Server 4 0 SP6 Disable Memopad Wireless Sync IT policy rule Description This rule specifies whether wireless data synchronization f...

Страница 145: ...turned off Default value The default value is Yes Usage If you change this rule to No the BlackBerry Enterprise Server logs all PIN messages in unencrypted format to the log file that you specify Make...

Страница 146: ...Minimum requirements C based BlackBerry device that is running BlackBerry Device Software version 2 7 Java based BlackBerry device that is running BlackBerry Device Software version 4 0 BlackBerry Ap...

Страница 147: ...g the PGP Support Package for BlackBerry smartphones For more information about using the PGP Support Package for BlackBerry smartphones see the PGP Support Package for BlackBerry Devices Security Tec...

Страница 148: ...is Automatic A BlackBerry device requests decrypted attachment information from the BlackBerry Enterprise Server automatically when users open PGP protected messages that contain attachments Minimum r...

Страница 149: ...oupWise does not support this rule PGP Force Digital Signature IT policy rule Description This rule specifies whether a BlackBerry device digitally signs all PGP protected messages that it sends Defau...

Страница 150: ...Novell GroupWise does not support this rule PGP Minimum Strong DH Key Length IT policy rule Description This rule specifies the minimum Diffie Hellman key size in bits to use with PGP protected messa...

Страница 151: ...cation Suite version 1 0 BlackBerry Device Software version 4 1 BlackBerry Enterprise Server version 4 0 SP2 Exceptions The BlackBerry Enterprise Server for Novell GroupWise does not support this rule...

Страница 152: ...irements Java based BlackBerry device BlackBerry Device Software version 5 1 BlackBerry Enterprise Server version 5 0 SP1 PGP Universal Enrollment Method IT policy rule Description This rule specifies...

Страница 153: ...rprise Server for Novell GroupWise does not support this rule PGP Universal Server Address IT policy rule Description This rule specifies the address of your organization s PGP Universal Server The PG...

Страница 154: ...at the user calls using voice activated dialing or Bluetooth technology or a phone number that the user provides manually To forward outgoing calls on devices you must configure the value of this rule...

Страница 155: ...a BlackBerry device user can change the web address for the BlackBerry Social Networking Application Proxy on a BlackBerry device Default value The default value is Yes A user can change the web addr...

Страница 156: ...rry Enterprise Server version 4 1 SP7 Allow TiVo for BlackBerry application IT policy rule Description This rule specifies whether the TiVo for BlackBerry application on the BlackBerry device is turne...

Страница 157: ...n Proxy that the BlackBerry Client for IBM Lotus Quickr uses for example https server_name port qkr 100 services Default value The default value is a null value Usage If you configure this rule you ca...

Страница 158: ...rule specifies whether to prevent the ecommerce content optimization engine for the BlackBerry Browser from running on a BlackBerry device Default value The default value is No Minimum requirements B...

Страница 159: ...ule specifies whether a BlackBerry device must prevent social networking applications from accessing organizer data Default value The default value is Yes Social networking applications such as Facebo...

Страница 160: ...rry device user can use the Tell a Friend feature in the BlackBerry Client for IBM Lotus Connections to recommend the BlackBerry Client for IBM Lotus Connections to another person Default value The de...

Страница 161: ...mum requirements BlackBerry Enterprise Server version 4 1 SP6 Lotus Connections Blogs Server IT policy rule Description This rule specifies the address of the server that hosts the IBM Lotus Connectio...

Страница 162: ...at hosts the IBM Lotus Connections Dogear component Default value The default value is a null value Usage If you configure this rule users can use the specified server address only If you do not confi...

Страница 163: ...ile system If you change this rule to Yes a user cannot run BlackBerry Podcasts on a device Minimum requirements Java based BlackBerry device BlackBerry Device Software 6 0 BlackBerry Desktop Software...

Страница 164: ...lackBerry Desktop Software 6 0 BlackBerry Enterprise Server 5 0 SP2 Secure Email policy group The IT policy rules in the Secure Email policy group apply to BlackBerry devices that are running the S MI...

Страница 165: ...a signed email message and the sender s email address does not appear in the certificate or the PGP key that was used to sign the email message Default value The default value is No Usage Consider ch...

Страница 166: ...plications can initiate internal connections for example to the BlackBerry MDS Connection Service Default value The default value is Yes Minimum requirements Java based BlackBerry device BlackBerry Ap...

Страница 167: ...t value The default value is No Usage For more information about the inactivity timeout visit www blackberry com go apiref to read the EventInjector class and Backlight enable method in the API refere...

Страница 168: ...erry Enterprise Server version 4 0 Allow Split Pipe Connections IT policy rule Description This rule specifies whether applications including third party applications can open internal and external co...

Страница 169: ...e to specify whether applications can access the persistent store API Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 3 6...

Страница 170: ...priority over the Force Smart Card Two Factor Authentication IT policy rule For example if you configure this rule to prevent smart card authentication but the Force Smart Card Two Factor Authenticati...

Страница 171: ...lackBerry devices that are running BlackBerry Device Software versions that are earlier than version 5 0 process the Disallowed setting in the same way that they process the Required setting If the co...

Страница 172: ...mory Media Files IT policy rule or instruct the BlackBerry device user to configure file encryption For BlackBerry devices that are running BlackBerry Device Software versions that are earlier than ve...

Страница 173: ...he device options Minimum requirements Java based BlackBerry device BlackBerry Device Software 6 0 BlackBerry Enterprise Server 5 0 SP2 Desktop Backup IT policy rule Description This rule specifies wh...

Страница 174: ...AES algorithm to encrypt and decrypt data that they send between them Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Connect version 4 0 interna...

Страница 175: ...e browser on a device Minimum requirements Java based BlackBerry device BlackBerry Device Software 6 0 BlackBerry Enterprise Server 5 0 SP2 Disable Certificate or Key Import From External Memory IT po...

Страница 176: ...version 4 0 SP6 Disable Forwarding Between Services IT policy rule Description This rule specifies whether to prevent a BlackBerry device user from forwarding or replying to a message on a BlackBerry...

Страница 177: ...re on a BlackBerry device is turned on Default value The default value is No Usage Change this rule to Yes to turn off the GPS feature and prevent applications on a BlackBerry device from accessing it...

Страница 178: ...erry Enterprise Server for Microsoft Exchange version 3 6 Exceptions The BlackBerry Enterprise Server for Novell GroupWise supports this rule in BlackBerry Device Software version 4 0 or later Disable...

Страница 179: ...l is High For BlackBerry devices that are running BlackBerry Device Software version 4 0 or later the next highest security level is Medium Minimum requirements Java based BlackBerry device BlackBerry...

Страница 180: ...or signed email messages Default value The default value is No Usage If you change this rule to Yes to send email messages the user must install the S MIME Support Package for BlackBerry smartphones o...

Страница 181: ...alltheS MIMESupportPackageforBlackBerrysmartphones or the PGP Support Package for BlackBerry smartphones on a BlackBerry device You must also turn on S MIME message processing on the BlackBerry Enterp...

Страница 182: ...logs an exception error message in the log file on the BlackBerry device resets the BlackBerry device and displays a Java 576 error removes the data that the application tries to save Attention If yo...

Страница 183: ...connected The wireless transceiver remains on Usage Change this rule to Radio disabled when USB device is connected to turn off the wireless transceiver while the BlackBerry device is connected to a...

Страница 184: ...her to prevent a user from using smart password entry when using two factor authentication If a user uses two factor authentication and a BlackBerry device password or authentication password is numer...

Страница 185: ...s of certificates on the BlackBerry device never expires Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 4 2 BlackBerry En...

Страница 186: ...erry Enterprise Server for Microsoft Exchange version 3 6 Exceptions The BlackBerry Enterprise Server for Novell GroupWise supports this rule in BlackBerry Device Software version 4 0 or later Disable...

Страница 187: ...or BlackBerry Desktop Manager to a device or media card If you change this rule to Yes a device cannot access a media card that is connected to the USB port on the device When you transfer files usin...

Страница 188: ...inimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 3 6 BlackBerry Enterprise Server for IBM Lotus Domino and Novell GroupWise...

Страница 189: ...ise Server for Novell GroupWise supports this rule for devices that are running BlackBerry Device Software 4 0 or later Encryption on On Board Device Memory Media Files IT policy rule Description If o...

Страница 190: ...edia directories if the media card requires encryption with a password that the user provides Change this rule to Encrypt to User Password including multimedia directories if the media card requires e...

Страница 191: ...ules are configured Password Required is configured to Yes Minimum Password Length is configured to 5 Suppress Password Echo is configured to Yes PGP Allowed Content Ciphers is configured to AES 256 b...

Страница 192: ...es of messages were received A user can specify whether to block public PIN messages on a BlackBerry device A user cannot specify whether to block organization specific PIN messages on a BlackBerry de...

Страница 193: ...lackBerry Enterprise Server version 4 0 SP3 Force Device Password Entry While User Authentication is Enabled IT policy rule Description This rule specifies whether a BlackBerry device user must type t...

Страница 194: ...Berry Enterprise Server include the IT policy viewer Change this rule to Yes if you want the IT Policy Viewer icon to appear in the Application folder on the device If you change this rule to Yes a us...

Страница 195: ...values The default value in the Default and Basic password security IT policies is No The default value in all other preconfigured IT policies is Yes Minimum requirements Java based BlackBerry device...

Страница 196: ...Usage If you change this rule to Yes a BlackBerry device displays a key store notification message during the cached period when the user opens or sends an uncached secure email message If a user ope...

Страница 197: ...ust have a smart card driver and a BlackBerry Smart Card Reader driver installed on the BlackBerry device Dependencies If you change this rule to Yes the BlackBerry Enterprise Server automatically con...

Страница 198: ...ry device uses this rule only if you configure the Password Required and Force Smart Card Two Factor Authentication IT policy rules to Yes Minimum requirements Java based BlackBerry device BlackBerry...

Страница 199: ...t Card Reader or when a proximity authenticator is out of range of the BlackBerry device Default value The default value in the Advanced security and Advanced security with No 3rd Party Applications I...

Страница 200: ...ackBerry Device Software version 3 6 BlackBerry Enterprise Server for IBM Lotus Domino and Novell GroupWise version 4 0 BlackBerry Enterprise Server for Microsoft Exchange version 3 6 Exceptions The B...

Страница 201: ...vice uses this rule only if you configure the Password Required Force Smart Card User Authentication and Force Smart Card Two Factor Challenge Response IT policy rules to Yes Minimum requirements Java...

Страница 202: ...terprise Server version 4 1 SP4 Minimal Encryption Key Store Security Level IT policy rule Description This rule specifies the minimum security level of the private key that a BlackBerry device uses t...

Страница 203: ...key store password when accessing the private key to sign messages only if the password is cleared from the key store cache If you change this rule to High security a BlackBerry device always prompts...

Страница 204: ...rise Server Default value The default value is No Usage A BlackBerry device can receive all email messages from the BlackBerry Enterprise Server that are not blocked at the BlackBerry device firewall...

Страница 205: ...on 1 0 BlackBerry Device Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Reset to Factory Defaults on Wipe IT policy rule Description This rule specifies whether a BlackBerry device...

Страница 206: ...BlackBerry device that cannot receive IT policy updates or IT administration commands delete user data after a specific period of time Dependencies If you configure this rule to prevent deleting user...

Страница 207: ...el is too low Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 4 2 BlackBerry Enterprise Server version 4 0 SP6 Security Se...

Страница 208: ...Enterprise Solution Security Technical Overview Default value The default value is a null value Usage To permit a third party encryption scheme to be used in conjunction with BlackBerry Enterprise So...

Страница 209: ...ction on the BlackBerry device is designed to protect the content protection decryption keys with both a private key that is stored on a smart card and the BlackBerry device password When a user turns...

Страница 210: ...ificate chains for the certificates that are used to sign messages that a BlackBerry device receives are strong enough Default value By default no algorithms are specified as weak Usage Specify a list...

Страница 211: ...specifies the encryption algorithms that a BlackBerry device can use to encrypt S MIME protected messages Default value The default value is to use all supported algorithms Usage To maintain compatib...

Страница 212: ...erry Device Software version 4 5 BlackBerry Enterprise Server version 4 1 SP5 S MIME Allowed Encryption Types IT policy rule Description This rule specifies the types of encryption that a BlackBerry d...

Страница 213: ...rule Description This rule specifies whether a BlackBerry device sends all S MIME protected messages digitally signed Default value The default value is No Minimum requirements Java based BlackBerry...

Страница 214: ...while the device is attached to a BlackBerry Smart Card Reader Default value The default value is No Minimum requirements Java based BlackBerry device S MIME Support Package for BlackBerry smartphones...

Страница 215: ...ed messages The permitted range is 512 through 1024 bits Default value The default value is 1024 bits Minimum requirements Java based BlackBerry device S MIME Support Package for BlackBerry smartphone...

Страница 216: ...The permitted range is 512 through 4096 bits Default value The default value is 1024 bits Minimum requirements Java based BlackBerry device S MIME Support Package for BlackBerry smartphones version 1...

Страница 217: ...vices Default value The default value is Yes Usage Change this rule to No to require that a BlackBerry device send browser data through your organization s BlackBerry Enterprise Server and to prevent...

Страница 218: ...s through your organization s BlackBerry Enterprise Server and to prevent a user from sending email messages using other email message services This rule does not prevent a user from receiving email m...

Страница 219: ...BlackBerry devices application the Google Talk for BlackBerry devices icon remains on the Home screen If a user tries to sign into the application a message appears indicating that the application ca...

Страница 220: ...y device configure the Allow Public Yahoo Messenger Services IT policy rule Minimum requirements BlackBerry Application Suite version 1 0 BlackBerry Enterprise Server version 4 0 SP4 Allow Public WLM...

Страница 221: ...ronize contacts with the network address book Usage Change the value of this rule to Enabled to permit a user to synchronize contacts with the network address book If your organization uses T Mobile a...

Страница 222: ...erprise Server version 4 0 SP3 Disable SIM Call Control IT policy rule Description This rule specifies whether to prevent a SIM card from changing a call a supplementary service request or an SMS text...

Страница 223: ...cy IT policy rule Description This rule specifies whether smart dialing for VoIP calls is available on a BlackBerry device Default setting The default setting is Yes Usage This rule is obsolete in Bla...

Страница 224: ...y Code IT policy rule Description This rule specifies the local country code for phone numbers Default value The default value is a null value Usage This rule is obsolete in BlackBerry Enterprise Serv...

Страница 225: ...BlackBerry Enterprise Server version 4 0 SP1 Smart Dialing Allow Device Changes IT policy rule Description This rule specifies whether a BlackBerry device user can change the smart dialing options Def...

Страница 226: ...ftware version 4 0 BlackBerry Enterprise Server version 4 0 TCP Password IT policy rule Description This rule specifies whether a default APN password must be used when a BlackBerry device uses TCP Th...

Страница 227: ...on This rule specifies whether a BlackBerry device and the BlackBerry Enterprise Server can use proxy mode TLS or proxy mode HTTPS Default value The default value is No Usage If you change this rule t...

Страница 228: ...servers Default value The default value is Prompt user on BlackBerry device Minimum requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Connect version 4 0 B...

Страница 229: ...nimum key size on the BlackBerry Enterprise Server to be higher than the minimum key size on a BlackBerry device the BlackBerry device continues to prompt the user to trust every secure web site that...

Страница 230: ...ts If you configure the minimum key size on the BlackBerry Enterprise Server to 1024 bits the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its...

Страница 231: ...default value on the BlackBerry Enterprise Server is 512 bits Usage If you configure the minimum key size on the BlackBerry Enterprise Server to be higher than the minimum key size on the BlackBerry d...

Страница 232: ...whether a BlackBerry device can use an algorithm with TLS that is not FIPS compliant Default value The default value is No Usage By default if you configure the FIPS Level IT policy rule to Level 2 a...

Страница 233: ...llow Users to Save Messages IT policy rule Description This rule specifies whether a BlackBerry device user can use visual voice mail to save or forward voice mail messages Default value The default v...

Страница 234: ...exity IT policy rule Description This rule specifies the minimum password length that a BlackBerry device user is required to type to access the TUI The permitted range is 0 to 16 digits Default value...

Страница 235: ...ackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 Disable VoIP User Profiles IT policy rule Description This rule specifies whether a user can create VoIP profiles on a...

Страница 236: ...BlackBerry Enterprise Server version 4 0 SP1 SIP Domain IT policy rule Description This rule specifies the SIP domain where the SIP user ID is valid Default value The default value is a null value Us...

Страница 237: ...IP realm value on a BlackBerry device must be the same as the SIP realm value that you specified on the SIP server This rule is made obsolete by BlackBerry Mobile Voice System Minimum requirements Jav...

Страница 238: ...uirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 SIP Server Name IT policy rule Description This rule specifies the name or IP...

Страница 239: ...version 4 0 SP1 SIP Server Transport IT policy rule Description This rule specifies the transport protocol that your organization s SIP server uses Default value The default value is UDP Usage Change...

Страница 240: ...his rule is made obsolete by BlackBerry Mobile Voice System Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 SIP Us...

Страница 241: ...te or delete the value To retain the value on the BlackBerry device verify that the updated IT policy uses the same value as this rule This rule is made obsolete by BlackBerry Mobile Voice System Mini...

Страница 242: ...e obsolete by BlackBerry Mobile Voice System Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 VoIP Enable Attended...

Страница 243: ...ifies whether a user can perform an unattended transfer to a VoIP call where the original call ends automatically when the user that transfers the call dials the transfer number on a BlackBerry device...

Страница 244: ...e might not be able to use a Wi Fi network that requires VPN access or it might require an alternative form of access control Usage Change this rule to Yes to require that a BlackBerry device use VPN...

Страница 245: ...kBerry device This rule is obsolete in BlackBerry Enterprise Server version 4 1 SP3 and later Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterp...

Страница 246: ...r version 4 1 SP3 VPN DNS Configuration IT policy rule Description This rule specifies your organization s VPN DNS configuration Default value The default value is Yes A BlackBerry device retrieves DN...

Страница 247: ...specifies the IP address or FQDN of your organization s VPN server Default value The default value is a null value Minimum requirements Java based BlackBerry device BlackBerry Device Software version...

Страница 248: ...rule Description This rule specifies the encryption algorithm that a BlackBerry device uses to authenticate the IKE exchanges Default value The default value is AES 128 Usage Change the value only if...

Страница 249: ...only if the hash method authentication code does not support SHA 1 160 bits Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server versi...

Страница 250: ...you change this rule to Medium security a BlackBerry device prompts the user for the key store password the first time only and from that point forward only prompts the user again after the user rese...

Страница 251: ...T policy rule Description This rule specifies whether Perfect Forward Secrecy is turned on for a BlackBerry device Default value The default value is Yes Usage Change the value only if your organizati...

Страница 252: ...m requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 VPN User Name IT policy rule Description This rule specifies the default...

Страница 253: ...evice verify that the updated rule uses the same value as this rule Dependencies You must change the Enable VPN IT policy rule to Yes so that a BlackBerry device can use this rule Minimum requirements...

Страница 254: ...BlackBerry Internet Service The previous name of this rule was BlackBerry Infrastructure WLAN Access Mode Default value The default value is Access does not require VPN A BlackBerry device can bypass...

Страница 255: ...ether to prevent a BlackBerry device user from adding Wi Fi profiles for SSIDs that you specify to a BlackBerry device The previous name of this rule was Blocked WLAN SSIDs Default value The default v...

Страница 256: ...irements Java based BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry Enterprise Server version 4 1 SP3 Disable GAN Selection Mode Editing IT policy rule Description This rule spec...

Страница 257: ...s whether a user can select the WAN preferred mode from the list of GAN selection modes on a BlackBerry device Default value The default value is No Usage Change this rule to Yes to prevent a user fro...

Страница 258: ...ry depending on which mobile network provider a BlackBerry device is using Usage Configure this rule to Yes to deny a BlackBerry device access to the BlackBerry Enterprise Server over a Wi Fi network...

Страница 259: ...Java based BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry Enterprise Server version 4 1 SP3 GAN Signal Strength Threshold IT policy rule Description This rule specifies the sign...

Страница 260: ...e GAN mode if the Wi Fi signal quality is high or medium If you choose High a BlackBerry device uses the GAN mode only if the Wi Fi signal quality is high Minimum requirements Java based BlackBerry de...

Страница 261: ...configure the value for the Wi Fi DHCP Configuration IT policy rule to Yes do not change the value for this rule to Yes Minimum requirements Java based BlackBerry device BlackBerry Device Software ve...

Страница 262: ...s Re Entry IT policy rule Description This rule specifies whether a BlackBerry device turns off the prompt for a user to re enter the Wi Fi credentials after authentication is not successful The previ...

Страница 263: ...was WLAN IP Address Default value The default value is a null value Usage A BlackBerry device uses this rule only if you change the Wi Fi DHCP Configuration IT policy rule to No Dependencies If you ch...

Страница 264: ...a user only once for the key store password so that the BlackBerry device can retrieve the private key and encrypt messages After the BlackBerry device retrieves the private key the BlackBerry device...

Страница 265: ...ork The previous name of this rule was WLAN Preshared Key Default value The default value is a null value Dependencies A BlackBerry device uses this rule only if you configure the Wi Fi Link Security...

Страница 266: ...ward Wi Fi profiles Dependencies A user can forward a Wi Fi profile using a PIN message only if you change the Allow Peer to Peer Messages IT policy rule to Yes and the Firewall Block Incoming Message...

Страница 267: ...e this rule to Yes Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 Wi Fi SSID IT policy rule Description This rule...

Страница 268: ...rry Enterprise Server version 4 0 SP1 Wi Fi User Name IT policy rule Description This rule specifies the user name for PEAP or LEAP security access on a BlackBerry device The previous name of this rul...

Страница 269: ...me value as the IT policy on the BlackBerry device Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 SP1 Wi Fi WEP Key 1...

Страница 270: ...ersion 4 0 BlackBerry Enterprise Server version 4 0 SP1 Wi Fi WEP Key 3 IT policy rule Description This rule specifies the password for WEP key 3 using the format xx xx xx xx xx The previous name of t...

Страница 271: ...ftware Updates policy group apply to the BlackBerry Device Software update process when a user connects a BlackBerry device to a computer Allow Web Based Software Loading IT policy rule Description Th...

Страница 272: ...e Software version 5 0 BlackBerry Enterprise Server version 5 0 SP1 Wireless Software Upgrades policy group Allow Non Enterprise Upgrade IT policy rule Description This rule specifies whether to permi...

Страница 273: ...rule specifies whether to prevent a BlackBerry device user from requesting available updates for the BlackBerry Device Software over the wireless network Default value The default value is No Usage Th...

Страница 274: ...sion 4 5 BlackBerry Enterprise Server version 4 1 SP4 Disallow Patch Download Over WAN IT policy rule Description This rule specifies whether to prevent a BlackBerry device from downloading updates fo...

Страница 275: ...ser from connecting to WTLS servers that have invalid certificates change this rule to Disable invalid connections If you want to permit a BlackBerry device user to connect to WTLS servers that have i...

Страница 276: ...ule Description This rule specifies whether to prevent a BlackBerry device from using weak algorithms over WTLS connections Default value The default value is Prompt user on BlackBerry device Usage If...

Страница 277: ...ise Server to 2048 bits the BlackBerry device continues to prompt the user to trust every secure web site that uses a key size in its certificate that is lower than 2048 bits This rule is obsolete in...

Страница 278: ...default value on the BlackBerry Enterprise Server is 512 bits Usage If you configure the minimum key size on the BlackBerry Enterprise Server to be higher than the minimum key size on a BlackBerry de...

Страница 279: ...y default if you configure the FIPS Level IT policy rule to 2 a BlackBerry device ignores this rule and uses only algorithms that are FIPS compliant Minimum requirements Java based BlackBerry device B...

Страница 280: ...Software version 4 0 0 BlackBerry Enterprise Server version 4 0 SP1 SIP Authentication ID configuration setting Description This setting specifies the SIP authentication ID that a BlackBerry device u...

Страница 281: ...n This setting specifies the network port number that a BlackBerry device listens for incoming SIP messages on Default value The default value is 5060 Usage This setting is made obsolete by the BlackB...

Страница 282: ...before the SIP registration process expires Default value The default value is 25 minutes Usage This setting is made obsolete by the BlackBerry Mobile Voice System Minimum requirements Java based Blac...

Страница 283: ...onfiguration setting Description This setting specifies the port number on your organization s SIP proxy server that the SIP proxy server uses to make network connections The permitted range is 0 to 6...

Страница 284: ...of SIP proxy server that a BlackBerry device can connect to Default value The default value is Generic SIP Usage Change this setting only if the SIP proxy server is not generic This setting is made o...

Страница 285: ...ainthevaluethattheusertypesontheBlackBerrydevice verifythattheupdatedITpolicyusesthesamevalueasthissetting This setting is made obsolete by the BlackBerry Mobile Voice System Minimum requirements Java...

Страница 286: ...setting Description This setting specifies the emergency number that a BlackBerry device can use on your organization s network Default value The default value is 911 Usage Two versions of this settin...

Страница 287: ...he BlackBerry Mobile Voice System Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 0 BlackBerry Enterprise Server version 4 0 SP1 VoIP Enable Call Hold configur...

Страница 288: ...VPN configuration setting Description This setting specifies whether the VPN client on a BlackBerry device is turned on Default value The default value is No The BlackBerry device might not be able t...

Страница 289: ...tificates to authenticate to your organization s VPN gateway Default value The default value is No Usage You must change the Enable VPN configuration setting to Yes so that a BlackBerry device can use...

Страница 290: ...e Validation configuration setting Description This setting specifies whether a BlackBerry device requires a certificate to authenticate with VPN gateways that support PKI based authentication using c...

Страница 291: ...uration setting Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 0 BlackBerry Enterprise Server version 4 1 SP2 VPN Domain Name configuration setting Descriptio...

Страница 292: ...on s VPN server only if the type of VPN client requires it Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 0 BlackBerry Enterprise Server version 4 1 SP2 VPN G...

Страница 293: ...ise Server version 4 1 SP3 VPN IKE Cipher configuration setting Description This setting specifies the encryption algorithm that a BlackBerry device uses to authenticate IKE exchanges Default value Th...

Страница 294: ...ntication code that a BlackBerry device can use Default value The default value is SHA 1 160 bits Usage Change this setting only if the hash method authentication code does not support SHA 1 160 bits...

Страница 295: ...or the key store password The BlackBerry device retrieves and stores in unencrypted format the private key with the VPN profile Usage If you change this setting to High security a BlackBerry device al...

Страница 296: ...0 BlackBerry Enterprise Server version 4 1 SP2 VPN PFS configuration setting Description This setting specifies whether PFS is turned on for a BlackBerry device Default value The default value is Yes...

Страница 297: ...default value is Full Visibility A user can view all the configuration settings of the VPN profile Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry...

Страница 298: ...etting The default value is 0 Dependencies If you change this setting you must also change the VPN DNS configuration setting to No and the Enable VPN configuration setting to Yes Minimum requirements...

Страница 299: ...nable VPN configuration setting to Yes so that a BlackBerry device can use this setting Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 0 BlackBerry Enterprise...

Страница 300: ...o Yes so that a BlackBerry device can use this configuration setting Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 0 BlackBerry Enterprise Server version 4 1...

Страница 301: ...an assign the Wi Fi profile to a user account and send the profile to a BlackBerry device Minimum requirements Java based BlackBerry device BlackBerry Device Software version 5 0 BlackBerry Enterprise...

Страница 302: ...i network Change this setting to No to prevent handovers between access points Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry Enterprise Server v...

Страница 303: ...ise Server version 4 1 SP3 Wi Fi Band Type configuration setting Description This setting specifies one or more band types that you configure the wireless access points of a specific SSID to operate o...

Страница 304: ...ss mode for a specific Wi Fi network and the IT policy rule to configure the access mode for other Wi Fi networks If you turn off access to the BlackBerry Infrastructure over a Wi Fi network using the...

Страница 305: ...ork configuration Default value The default value is Yes DHCP is turned on Usage If your organization uses a Wi Fi network that includes subnets turn on DHCP to permit roaming between subnets Minimum...

Страница 306: ...n ThissettingspecifiesthetypeofprovisioningmethodthataBlackBerry devicecanusewhenitauthenticatestoaWi Fi network using EAP FAST authentication with PAC Default value The default value is Anonymous The...

Страница 307: ...in browser is available on a BlackBerry device Default value The default value is No Usage Change this setting to Yes to permit a user to log in to a captive portal using a BlackBerry device This sett...

Страница 308: ...s the IP address for example 10 0 0 1 that a BlackBerry device can use if DHCP on the BlackBerry device is turned off Default value The default value is a null value Usage A BlackBerry device uses thi...

Страница 309: ...e If you configure this setting to Medium security a BlackBerry device prompts a user only once for the key store password so that the BlackBerry device can retrieve the private key and encrypt messag...

Страница 310: ...setting only if you change the Wi Fi DHCP Configuration configuration setting to No Dependencies If you configure the Wi Fi DHCP Configuration configuration setting to Yes do not change this setting t...

Страница 311: ...ckBerry device displays only the profile name WhenyouconfigurethissettingtoCredentialsvisibility theBlackBerrydevicedisplaysonlytheprofilenameandlogininformation of the user Minimum requirements Java...

Страница 312: ...sed BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry Enterprise Server version 4 1 SP3 Wi Fi Secondary DNS configuration setting Description This setting specifies the secondary D...

Страница 313: ...ault value is a null value Usage If you do not specify the Subject field for a server certificate the BlackBerry device accepts any valid server certificate Minimum requirements Java based BlackBerry...

Страница 314: ...to Yes do not change this setting to Yes Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 0 BlackBerry Enterprise Server version 4 1 SP2 Wi Fi Token Serial Numb...

Страница 315: ...setting Description This setting specifies the password for PEAP or LEAP authentication on a BlackBerry device Default value The default value is a null value Usage Configure this setting if you want...

Страница 316: ...her5or13pairsofhexadecimaldigits 0to9andAtoF thatyouseparatewithacolon forexample AB CD EF 01 23 or AB CD EF 01 23 45 67 89 AB CD EF 01 23 Minimum requirements Java based BlackBerry device BlackBerry...

Страница 317: ...xx xx Default value The default value is null Usage Validvaluesareeither5or13pairsofhexadecimaldigits 0to9andAtoF thatyouseparatewithacolon forexample AB CD EF 01 23 or AB CD EF 01 23 45 67 89 AB CD E...

Страница 318: ...um requirements Java based BlackBerry device BlackBerry Application Suite version 1 0 BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 Are External Network Connections A...

Страница 319: ...s and access call logs on a BlackBerry device You can configure this rule to prevent an application from making calls on a device or to prompt a user whether the user wants to permit the call before t...

Страница 320: ...ication to send all of a user s personal information from a BlackBerry device Default value The default value is Allowed Minimum requirements Java based BlackBerry device BlackBerry Application Suite...

Страница 321: ...for Bluetooth API Allowed application control policy rule Description This rule specifies whether an application can access the Bluetooth SPP API Default value The default value is Allowed Dependenci...

Страница 322: ...cess key store items that are stored at the medium security level The application must prompt a BlackBerry device user for the key store password when it tries to access the private key for the first...

Страница 323: ...ations that are developed using the Plazmic Content Developer s Kit as themes on a BlackBerry device Default value The default value is Allowed Minimum requirements Java based BlackBerry device BlackB...

Страница 324: ...This rule specifies whether an application can change configuration and user settings on a BlackBerry device Default value The default value is Allowed Minimum requirements Java based BlackBerry devic...

Страница 325: ...er applications on a BlackBerry device Default value The default value is No Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 2 1 BlackBerry Enterprise Server ver...

Страница 326: ...olicy rule Description This rule specifies the internal domain names that an application can establish a connection to Default value The default value is a null value Minimum requirements Java based B...

Страница 327: ...ifywww google comandwww yahoo comasdomainsforwhichanapplicationcanuseabrowser filter for search engines Default value The default value is a null value Minimum requirements Java based BlackBerry devic...

Страница 328: ...Optional Minimum requirements Java based BlackBerry device BlackBerry Device Software version 4 0 BlackBerry Enterprise Server version 4 0 Is Access to the Module Management API Allowed application c...

Страница 329: ...FIPS compliance for the embedded cryptographic module that is required for basic operation of the BlackBerry device Control application installation and use on BlackBerry devices Prevent BlackBerry de...

Страница 330: ...on secure passwords for example password usernames and organization s names Set Password Timeout 5 minutes User Can Change Timeout No Delete all user data on the BlackBerry device if the user types th...

Страница 331: ...s permitted before the BlackBerry device locks Defining the encryption strength that the BlackBerry device uses to protect data Scenario Example IT policy rule Example value Protect user and applicati...

Страница 332: ...sending SMS text messages Users can still receive SMS text messages Allow SMS No Prevent users from forwarding or replying to messages using a different BlackBerry Enterprise Server Disable Forwardin...

Страница 333: ...d party Java application to create public external network connections and permit connections to external domains without prompting users for a password on their BlackBerry devices Are External Networ...

Страница 334: ...le Required Remove a third party Java application from BlackBerry devices over the wireless network Disposition application control policy rule Required Prevent users from turning on a custom theme th...

Страница 335: ...M value added applications if you want to remove the RIM value added applications from BlackBerry devices Configure the Disable RIM Value Added Applications IT policy rule to Yes ecommerce content opt...

Страница 336: ...II American Standard Code for Information Interchange AVRCP Audio Video Remote Control Profile BCC blind carbon copy BlackBerry MDS BlackBerry Mobile Data System BSM browser session manager CAST Compu...

Страница 337: ...Extensible Authentication Protocol Flexible Authentication via Secure Tunneling EAP TLS Extensible Authentication Protocol Transport Layer Security EAP TTLS Extensible Authentication Protocol Tunneled...

Страница 338: ...change IMEI International Mobile Equipment Identity IOT interoperability test IP Internet Protocol IPSec Internet Protocol Security LEAP Lightweight Extensible Authentication Protocol LED light emitti...

Страница 339: ...tected Extensible Authentication Protocol PFS Perfect Forward Secrecy PIM personal information management PIN personal identification number PKI Public Key Infrastructure PSK pre shared key RNG random...

Страница 340: ...Service SPP Serial Port Profile SSID service set identifier TCP Transmission Control Protocol TLS Transport Layer Security TUI telephone UI UDP User Datagram Protocol UID unique identifier USB Univers...

Страница 341: ...WAP Wireless Application Protocol WEP Wired Equivalent Privacy WLAN wireless local area network WTLS Wireless Transport Layer Security Policy Reference Guide Glossary 339...

Страница 342: ...Provide feedback 7 To provide feedback on this deliverable visit www blackberry com docsfeedback Policy Reference Guide Provide feedback 340...

Страница 343: ...for any typographical technical or other inaccuracies errors or omissions in this documentation In order to protect RIM proprietary and confidential information and or trade secrets this documentation...

Страница 344: ...AL PURPOSE OF THIS AGREEMENT OR OF ANY REMEDY CONTAINED HEREIN AND B TO RIM AND ITS AFFILIATED COMPANIES THEIR SUCCESSORS ASSIGNS AGENTS SUPPLIERS INCLUDING AIRTIME SERVICE PROVIDERS AUTHORIZED RIM DI...

Страница 345: ...agreement with RIM applicable thereto NOTHINGINTHISDOCUMENTATIONISINTENDEDTOSUPERSEDEANYEXPRESSWRITTENAGREEMENTSORWARRANTIES PROVIDED BY RIM FOR PORTIONS OF ANY RIM PRODUCT OR SERVICE OTHER THAN THIS...

Отзывы: