Assign the BEMS-Connect SSL certificate to users

By default, BEMS-Connect uses a self-signed certificate that is generated by the BEMS installer.
  1. Complete one of the following tasks:
    • If you use the default SSL certificate generated by the BEMS installer,
      1. In the BlackBerry Enterprise Mobility Server Dashboard, under BEMS System Settings, click SSL Certificate.
      2. Click Download SSL Certificate. By default, the BemsCert.cer file is saved to the Downloads folder.
    • If you use your own SSL certificate, export the SSL certificate chain from the Microsoft Management Console (MMC). If you don't know which certificate chain to download, in a command prompt type netsh http show sslcert to confirm the certificate hash, then use the MMC to locate the certificate where the certificate thumbprint is the same as the certificate hash.
      1. Open the Microsoft Management Console (MMC).
      2. Click Console Root.
      3. Click File > Add/Remove Snap-in.
      4. In the Available snap-ins column, click Certificates > Add.
      5. In the Certificates snap-in wizard, select Computer account. Click Next.
      6. On the Computer > Select Computer screen, select Local Computer. Click Finish.
      7. Click OK.
      8. In the MMC, expand Certificates (Local Computer) > Personal.
      9. Double-click the SSL certificate.
      10. Click Certification Path.
      11. Click the root certificate. The root certificate is the first item in the Certificate hierarchy.
      12. Click View Certificate.
      13. Click the Details tab.
      14. Click Copy to File.
      15. Click Next.
      16. Enter name for the certificate and export it to your desktop.
      17. Click Save.
      18. Click Finish.
      19. Click OK.
  2. Create a CA certificate profile for the BEMS Self-Signed certificate, or create individual CA certificate profiles for the CA Root certificate and any CA Intermediate certificates. Assign the profiles to users or user groups. For instructions on creating a CA certificate profile and assigning it to users or user groups, see the BlackBerry UEM administration content.