Prerequisites for installing BlackBerry UEM 12.21 MR1 or 12.23 in a BSI-certified environment

Complete the following tasks before you install BlackBerry UEM:

Task

Instructions

Verify UEM preinstallation and hardware requirements.

Verify port and firewall configurations

  • Verify that UEM can use the required listening ports. See How BlackBerry UEM selects listening ports during installation.
  • Open the necessary ports in your organization's firewall. See Port requirements.
  • During the UEM installation process, you will enable an encrypted connection between ​​​​​​UEM​​​​ and ​​​​​​Microsoft SQL Server. To establish this encrypted connection, the UEM Core must be able to reach the revocation endpoints configured in the SQL Server certificate (OCSP responder or CRL distribution point). Verify that your firewall allows this connection from the computer that will host the UEM Core component. If this connection cannot be established during the installation or startup process, the following error is written to the UEM log files: "revocation status due to network error".

Configure permissions for the Windows service account.

See Configure permissions for the service account for UEM.

Configure UEM database connections.

See Configure connections for the UEM database.

Install the required JRE.

Install JRE 17 on the computer that will host UEM and set an environment variable for the Java location.

Download the UEM software.

  • In myAccount, navigate to Product Resources > Software Downloads to download the installation package (.zip) for UEM version 12.21.1 or 12.23. Copy the SHA256 value that is displayed for the download package.
  • Use your preferred tool to determine the SHA256 value of the UEM download package and validate that it matches the SHA256 value that you copied from myAccount (for example, in Windows PowerShell you can use get-filehash <file_path_of_UEM_zip_package>).