Configure the Connect service to receive SSL communications for a new installation
By default, SSL is enabled when you install the Connect service and runs securely using SSL/TLS (HTTPS) to communicate with the BlackBerry Connect app over port 8082. By default, the BEMS installer generates a secure certificate that is bound to port 8082. Optionally, you can choose to manually create a secure certificate that you must import to BEMS and bind to port 8082 or another available port. If you upgrade from BEMS 2.10 or earlier, see Options to configure the Connect service to receive SSL communications from an upgraded BEMS instance for available options.
If you installed the Connect service on multiple computers, complete this task on each computer that hosts the Connect service.
- Use the default BEMS-Connect SSL certificate that is generated by the BEMS installer and the default port number. In this scenario, you must Assign the BEMS-Connect SSL certificate to users.
- Use the default BEMS-Connect SSL certificate that is generated by the BEMS installer, but your environment requires that you use a different port number. In this scenario, you must complete the following steps:
- Unbind the SSL certificate from port 8082.
- Bind the SSL certificate to the Connect service SSL port.
- Update the port number to enable SSL for BEMS Common and Connect service.
- Assign the BEMS SSL certificate to users.
- Configure the BlackBerry Connect app to send requests over SSL. For more information, see 'Configuring BlackBerry Connect app settings' in the BlackBerry Connect administration content.
- Use your own SSL certificate and the default port number. In this scenario you must complete the following steps:
- Create a CSR request.
- Submit a CSR request to a certificate authority. You must install the certificate on the server that generated the CSR.
- Import the signed certificate to the computer that hosts the Connect service.
- Import the certificate into the Java keystore. For more information, see 'Keystore commands' in the BEMS-Core configuration content.
- Bind the SSL certificate to the Connect service SSL port
- Add the certificate friendly name to the BlackBerry Connect server configuration file.
- Assign the BEMS-Connect SSL certificate to users
- Configure the BlackBerry Connect app to send requests over SSL. For more information, see 'Configuring BlackBerry Connect app settings' in the BlackBerry Connect administration content.