Configuring how BlackBerry devices authenticate to content servers
If you configured the content servers in your organization's environment to use an authentication protocol to authenticate the sources of the data requests that they receive, you can control how BlackBerry® devices authenticate to content servers to receive application data and application updates.
Configure how BlackBerry devices authenticate to content servers
You can configure whether BlackBerry® devices authenticate to content servers directly, or whether the BlackBerry MDS Connection Service authenticates to content servers on behalf of BlackBerry devices. If you configure BlackBerry devices to authenticate directly to content servers but you do not configure an authentication method for BlackBerry MDS Connection Service
connections,
authenticated BlackBerry devices prompt users to provide login information every 60 minutes. The BlackBerry
devices prompt users only if the connection to the content server persists for more than 60 minutes.
Configure the BlackBerry MDS Connection Service to authenticate BlackBerry devices to content servers that use NTLM
Before you begin: Configure the BlackBerry® MDS Connection Service to authenticate to content servers on behalf of BlackBerry devices.
- Navigate to <drive>:\Program Files\Research In Motion\BlackBerry Enterprise Server\MDS\Servers\Instance\config.
- Configure the MdsLogin.conf file.
For more information about the Java® Authentication and Authorization Service configuration file, visit http://java.sun.com/javase/6/docs/technotes/guides/security/jgss/tutorials/LoginConfigFile.html.
Configure the BlackBerry MDS Connection Service to authenticate BlackBerry devices to content servers that use Kerberos
Before you begin: Configure the BlackBerry® MDS Connection Service to authenticate to content servers on behalf of BlackBerry devices.
- Navigate to <drive>:\Program Files\Research In Motion\BlackBerry Enterprise Server\MDS\Servers\Instance\config.
- Configure the krb5.conf file.
For more information about the Kerberos™ 5 configuration file, visit web.mit.edu/kerberos/www/krb5-1.3/krb5-1.3.3/doc/krb5-admin.html#krb5.conf.
Configure the BlackBerry MDS Connection Service to authenticate BlackBerry devices to content servers that use LTPA
BlackBerry®
devices
that are running BlackBerry®
Device Software version 3.8 or later manage how HTTP cookies are stored and used to authenticate to content servers that use LTPA authentication technology.
For BlackBerry
devices that use previous versions of the BlackBerry Device Software, you must permit the BlackBerry MDS Connection Service
to manage HTTP cookie storage on BlackBerry
devices.
Before you begin: Configure the BlackBerry MDS Connection Service to authenticate to the content servers in your organization's environment on behalf of BlackBerry
devices.
- In the BlackBerry Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.
- Click MDS Connection Service.
- Click Edit component.
- On the HTTP tab, in the Protocol service information section, in the Cookie support enabled drop-down list, click Yes.
- Click Save all.
Configure the BlackBerry MDS Connection Service to authenticate BlackBerry devices to the RSA Authentication Manager
When you turn on RSA® authentication, users must type their login information on their BlackBerry® devices before they can access intranet or Internet content. After users are authenticated, if proxy authentication is configured, the BlackBerry devices prompt users to authenticate to the proxy server.
Before you begin: Configure the BlackBerry MDS Connection Service to authenticate to the content servers in your organization's environment on behalf of BlackBerry devices.