Resumo do conteúdo contido na página número 1
User Guide Supplement
S/MIME Support Package for BlackBerry Smartphones
BlackBerry 8700 Series
Resumo do conteúdo contido na página número 2
SWD-327206-0324102627-001
Resumo do conteúdo contido na página número 3
Contents Certificates..............................................................................................................................................................................................................................................3 Certificate basics.............................................................................................................................................................................................................................
Resumo do conteúdo contido na página número 4
2
Resumo do conteúdo contido na página número 5
Certificates Certificate basics Download a certificate from an LDAP certificate server 1. In the device options, click Security Options. 2. Click Certificates. 3. Click the trackwheel. 4. Click Fetch Certificates. 5. Specify the search criteria. 6. Click the trackwheel. 7. Click Search. 8. Click a certificate. 9. Click Add Certificate to Key Store. View properties for a certificate 1. In the device options, click Security Options. 2. Click Certificates. 3. Click a certificate. 4. Click Details.
Resumo do conteúdo contido na página número 6
Public Key Type: This field displays the standard to which the public key complies. Your device supports RSA®, DSA, Diffie-Hellman, and ECC keys. Subject: This field displays information about the certificate subject. Issuer: This field displays information about the certificate issuer. Serial Number: This field displays the certificate serial number in hexadecimal format. Key Usage: This field displays approved uses of the public key. Subject Alt Name: This field displays an alternate email add
Resumo do conteúdo contido na página número 7
5. Click Send via Email or Send via PIN. Delete a certificate 1. In the device options, click Security Options. 2. Click Certificates. 3. Highlight a certificate. 4. Click the trackwheel. 5. Click Delete. View the certificate chain for a certificate 1. In the device options, click Security Options. 2. Click Certificates. 3. Highlight a certificate. 4. Click the trackwheel. 5. Click Show Chain. Certificate status Certificate status indicators : The certificate has a corresponding private key that
Resumo do conteúdo contido na página número 8
4. Click the trackwheel. 5. Click Fetch Status or Fetch Chain Status. Change the trust status of a certificate 1. In the device options, click Security Options. 2. Click Certificates. 3. Highlight a certificate. 4. Click the trackwheel. 5. Click Trust or Distrust. 6. If necessary, perform one of the following actions: • To trust the highlighted certificate, click Selected Certificate. • To trust the highlighted certificate and all the other certificates in the chain, click Entire Chain. Revoke a
Resumo do conteúdo contido na página número 9
Superseded: A new certificate is replacing an existing certificate. Cessation of Operation: The certificate subject no longer requires the certificate. Certificate Hold: You want to revoke the certificate temporarily. Certificate options Change the display name for a certificate 1. In the device options, click Security Options. 2. Click Certificates. 3. Highlight a certificate. 4. Click the trackwheel. 5. Click Change Label. 6. Type a display name for the certificate. 7. Click OK. Add an email a
Resumo do conteúdo contido na página número 10
3. Click the trackwheel. 4. Click Fetch Certificates. 5. Click the trackwheel. 6. Click Options. 7. Change the Prompt for Label field to No. 8. Click the trackwheel. 9. Click Save. When you add a certificate, your BlackBerry® device uses the certificate subject as the name for the certificate. Turn off the fetch status prompt that appears when you add a certificate to the key store 1. In the device options, click Security Options. 2. Click Certificates. 3. Click the trackwheel. 4. Click Fetch Ce
Resumo do conteúdo contido na página número 11
Certificate troubleshooting I cannot download a certificate If you changed the connection type that your BlackBerry® device uses to connect to the LDAP certificate server, try switching to the default connection type. 9
Resumo do conteúdo contido na página número 12
10
Resumo do conteúdo contido na página número 13
Certificate servers Add a certificate server 1. In the device options, click Security Options. 2. Click Certificate Servers. 3. Click the trackwheel. 4. Click New Server. 5. Specify information for the certificate server. 6. Click the trackwheel. 7. Click Save. Change connection information for a certificate server 1. In the device options, click Security Options. 2. Click Certificate Servers. 3. Highlight a certificate server. 4. Click the trackwheel. 5. Click Edit. 6. Change connection informa
Resumo do conteúdo contido na página número 14
Connection Type: Specify whether your BlackBerry® device uses an SSL connection or a TLS connection to connect to the certificate server. Connection options for OCSP and CRL servers Friendly Name: Type a display name for the certificate server. Server URL: Type the web address of the certificate server. Send connection information for a certificate server 1. In the device options, click Security Options. 2. Click Certificate Servers. 3. Highlight a certificate server. 4. Click the trackwheel. 5.
Resumo do conteúdo contido na página número 15
Key stores About the key store The key store on your BlackBerry® device might store the following items. To access these items in the key store, you must type a key store password. • personal certificates (certificate and private key pairs) • certificates that you download using the certificate synchronization tool of the BlackBerry® Desktop Manager • certificates that you download from an LDAP certificate server • certificates that you add from a message • personal PGP® keys (public and private
Resumo do conteúdo contido na página número 16
3. Change the Key Store Address Injector field to Enabled. 4. Click the trackwheel. 5. Click Save. Change the service that your device uses to download certificates Depending on your organization, you might not be able to change the service that you use to download certificates. For more information, contact your administrator. 1. In the device options, click Security Options. 2. Click Key Stores. 3. Change the Certificate Service field. 4. Click the trackwheel. 5. Click Save. Turn off automatic
Resumo do conteúdo contido na página número 17
2. Click Key Stores. 3. Change the Accept Unverified CRLs field to No. 4. Click the trackwheel. 5. Click Save. Your BlackBerry® device rejects certificate revocation lists from CRL servers that the BlackBerry® MDS Connection Service cannot verify. 15
Resumo do conteúdo contido na página número 18
16
Resumo do conteúdo contido na página número 19
S/MIME-protected messages S/MIME-protected message basics About signing and encrypting messages You can digitally sign or encrypt messages to add another level of security to email messages and PIN messages that you send from your BlackBerry® device. Digital signatures are designed to help recipients verify the authenticity and integrity of messages that you send. When you digitally sign a message using your private key, recipients use your public key to verify that the message is from you and t
Resumo do conteúdo contido na página número 20
Add a certificate from a message 1. In a message, highlight a digital signature indicator. 2. Click the trackwheel. 3. Click Import Sender’s certificate. Add a certificate from an attachment 1. In a message, click the certificate attachment. 2. Click Retrieve Certificate Attachment. 3. Click the certificate. 4. Click Import Certificate. Add connection information for a certificate server from a message 1. In a message, highlight the certificate server indicator. 2. Click the trackwheel. 3. Click