• Ability to use a password, which the sender and recipient each know, to encrypt S/MIME-protected email messages or
PIN messages
• Ability to read S/MIME certificates that are stored on a smart card
Configure the BlackBerry Enterprise Solution to support S/MIME
encryption
1.
Configure encryption options for S/MIME-protected messages on the BlackBerry Enterprise Server.
2.
If required, configure message classifications for email messages.
3.
If required, configure the BlackBerry MDS Connection Service to retrieve certificates and the status of certificates
from LDAP servers, DSML certificate servers, OCSP servers, or CRL servers.
4.
Instruct users to install the S/MIME Support Package for BlackBerry smartphones on BlackBerry devices.
5.
Perform one of the following tasks:
• Instruct users to add the Certificate Synchronization Manager to the BlackBerry Desktop Manager so that the
BlackBerry Desktop Manager can manage certificates for the BlackBerry devices.
• Configure the BlackBerry Enterprise Server to permit users to enroll certificates over the wireless network.
Related information
Configuring certificate server information for the BlackBerry MDS Connection Service,
193
Enforcing secure messaging using classifications,
65
Configuring BlackBerry devices to enroll certificates over the wireless network,
217
Configure encryption options for S/MIME-protected messages
You can configure encryption options to control how the BlackBerry Enterprise Server processes S/MIME-protected
messages.
1.
In the BlackBerry Administration Service, on the
Servers and components
menu, expand
BlackBerry Solution
topology > BlackBerry Domain > Component view > Email
.
2.
Click the instance that you want to change.
3.
Click
Edit instance
.
4.
On the
Messaging
tab, in the
Security settings
section, perform any of the following actions:
• To require that the BlackBerry Enterprise Server encrypts messages using S/MIME encryption for a second time
when the BlackBerry Enterprise Server processes S/MIME-protected messages that an S/MIME-enabled
application weakly encrypted or only signed, in the
Turn on S/MIME encryption on signed and weakly encrypted
messages
drop-down list, click
True
.
• To permit BlackBerry device users that have email applications that do not support S/MIME to read the text of an
S/MIME-protected message, in the
Send S/MIME messages in clear-signed format
drop-down list, click
True
.
Administration Guide
Configuring security options
63