Data flow: Activating BBM Enterprise on a device
- You perform the following actions:
- Create a BBM Enterprise profile.
- Review the BBM Enterprise activation email template and modify it if necessary.
- Add a user to BlackBerry UEM as a local user account or using the account information retrieved from your company directory.
- Assign the BBM Enterprise profile to a user. UEM pushes the assigned BBM Enterprise profile through the BlackBerry Infrastructure to BBM Enterprise.
- UEM pushes the assigned BBM Enterprise profile through the BlackBerry Infrastructure to BBM Enterprise.
- Use one of the following options to provide the user with activation details:
- Automatically generate a device activation password and send an email with activation instructions for the user.
- Set a device activation password and communicate the username and password to the user directly or by email.
- Don't set a device activation password and communicate the BlackBerry UEM Self-Service address to the user so that they can set their own activation password.
- The user downloads and installs BBM Enterprise on their device. After it is installed, the user opens BBM Enterprise and enters the email address and activation password. If provided, the user can click a link in the activation email to be taken directly to BBM Enterprise.
- The BBM Enterprise client on the device performs the following actions:
- Establishes a connection to the BlackBerry Infrastructure
- Sends a request for activation information to the BlackBerry Infrastructure .
- The BlackBerry Infrastructure performs the following actions:
- Verifies that the user is a valid, registered user.
- Retrieves the UEM address for the user.
- Sends the address to the BBM Enterprise client.
- The BBM Enterprise client performs the following actions:
- Establishes a connection with UEM using HTTP Connect over port 443.
- Generates a shared symmetric key that is used to protect the CSR (certificate signing request) and responds to UEM using the activation password and EC-SPEKE.
- Creates an encrypted CSR and HMAC as follows:
- Generates a key pair for the certificate.
- Creates a PKCS#10 CSR that includes the public key of the key pair.
- Encrypts the CSR using the shared symmetric key and AES-256 in CBC mode with PKCS#5 padding.
- Computes an HMAC of the encrypted CSR using SHA-256 and appends it to the CSR.
- Sends the encrypted CSR and HMAC to BlackBerry UEM.
- UEM performs the following actions:
- Verifies the HMAC of the encrypted CSR and decrypts the CSR using the shared symmetric key.
- Retrieves the username, work space ID, and your organization’s name from the UEM database.
- Packages a client certificate using the information it retrieved and the CSR that the device sent.
- Signs the client certificate using the enterprise management root certificate.
- Encrypts the client certificate, enterprise management root certificate, and the UEM URL using the shared symmetric key and AES-256 in CBC mode with PKCS#5 padding.
- Computes an HMAC of the encrypted client certificate, enterprise management root certificate, and the UEM URL and appends it to the encrypted data.
- Sends the encrypted data and HMAC to the device.
- The BBM Enterprise client performs the following actions:
- Verifies the HMAC.
- Decrypts the data it received from UEM.
- Stores the client certificate and the enterprise management root certificate encrypted in BBM Enterprise.
- Sends the device information (if it is available) and BBM Enterprise software information to UEM.
- The UEM Core assigns the BBM Enterprise device to a UEM instance in the domain.
- The BBM Enterprise client performs the following actions:
- Retrieves a SCEP profile from UEM. This profile is used to trigger an assisted SCEP procedure in order to obtain a device-specific certificate, which will be used to access UEM and servers that are providing BBM Enterprise services.
- The BBM Enterprise snap-in returns a SCEP profile (default or configured).
- The BBM Enterprise client performs an assisted SCEP operation against the BlackBerry Enterprise Identity service mediated by UEM.
- The resulting certificate, specific to a BBM Enterprise device, is sent back to the BBM Enterprise client.
- The activation process is complete.
- The BBM Enterprise client uses the device certificate to connect to the BBM Enterprise infrastructure and retrieves the BBM Enterprise policy configured for the user and completes the activation.