Install BlackBerry UEM version 12.21 MR1 or 12.23 in a BSI-certified environment
- Review the Requirements and considerations for a BSI-certified UEM environment.
- Complete the Prerequisites for installing BlackBerry UEM 12.21 MR1 or 12.23 in a BSI-certified environment.
- When you follow the steps below to install UEM, you will enable an encrypted connection between UEM and Microsoft SQL Server. To enable the trust for the connection, export the root CA certificate that issued the SQL Server certificate and store it on the server where you will install UEM. You will provide this certificate's path during the UEM installation process (step 10). The file path where you store the certificate must not contain any spaces.
- Log in to UEM for the first time.
- Create an LDAP client certificate used for mutual authentication and connect to an LDAP directory.
- See the Guide to setting up BlackBerry UEM for a reference that walks you through the resources for setting up and administering a UEM environment. For additional setup tasks that must be completed for a BSI-certified environment, see Configure BlackBerry UEM for a BSI-certified environment.
- If you want to install multiple instances of UEM, repeat the installation steps above on a different computer, but at step 9 you must run the following commands instead:
cd <extracted_UEM_installer_package>\db\Database\toolsbeskeytool.bat importkey -key <key_value> -server <database_server_hostname> -instance <database_instance> -port <database_port> -name <database_name> -authtype INTEGRATED -user <database_user_name>
<key_value> is the database encryption key that was generated in step 9. If you did not save the generated key, you can run the following command on the computer where you installed the first UEM instance to display the key:cd <extracted_UEM_installer_package>\db\Database\toolsbeskeytool.bat printkey