BlackBerry Dynamics SDK for Android version 15.x

What's new in BlackBerry Dynamics SDK for Android version 15.1

Feature

Description

Changes to Android software requirements

  • This release adds support for Android 17.
  • Android OS 12 is no longer supported; Android OS 13 or later is required.

Security updates

  • Support for TLS 1.3 with AES-GCM suites (AES-CCM is not supported).
  • Updates to SQLite, cURL, and OpenSSL libraries.

Calling GDAndroid.activityInit()

Your BlackBerry Dynamics app must call GDAndroid.activityInit() in the onCreate() method of every Activity, after super.onCreate(). In the BlackBerry Dynamics SDK for Android version 15.0 and earlier, your app could invoke GDAndroid.activityInit() before super.onCreate(), but this is no longer supported. Calling GDAndroid.activityInit() before super.onCreate() results in a GDInitializationError.

AI writing tools disabled

BlackBerry plans to introduce a BlackBerry Dynamics profile setting in an upcoming UEM release to control whether AI writing tools are enabled for BlackBerry Dynamics apps. In the interim, AI writing tools are not enabled for BlackBerry Dynamics apps.

What's new in BlackBerry Dynamics SDK for Android version 15.0

Feature

Description

UX enhancements

Various UI elements have been updated to reflect the latest BlackBerry branding and the latest styles for Android.

Support for new BlackBerry Dynamics profile settings

This release supports a BlackBerry Dynamics profile setting added in UEM version 12.21, "Open files unencrypted in other selected non-Dynamics apps". This setting can be used to allow or block the transfer and opening of unencrypted files from BlackBerry Dynamics apps to selected non-BlackBerry Dynamics apps.

OpenSSL upgrade

  • This release of the BlackBerry Dynamics SDK for Android has been upgraded to OpenSSL 3.5.4 to enforce stronger security, access current algorithms and features, and comply with regulatory requirements.
  • OpenSSL 3.x introduces stricter flag-handling behavior. Every flag that is semantically relevant to an operation must be provided at every call site. Not providing a required flag can cause silent data corruption or signature-verification failures. For more information, see the details for GDCryptoPKCS7 in BlackBerry Dynamics SDK for Android: Crypto C Programming Interface List and the OpenSSL Documentation for PKCS7_sign. Flag combinations that callers should review include:
    • Binary (non-MIME) signature: Pass GDPKCS7_BINARY to GDPKCS7_add_signer, GDPKCS7_final, and GDPKCS7_write when signing arbitrary binary data. Without this flag, OpenSSL performs MIME CRLF canonicalization, altering the bytes that are hashed and producing an invalid signature.
    • Detached signature: Pass GDPKCS7_DETACHED | GDPKCS7_BINARY when the signed content must travel separately from the PKCS#7 structure. During verification, the original content must be provided explicitly with the indata parameter of GDPKCS7_verify. Not doing so can result in a verification error.
  • The BlackBerry Dynamics SDK for Android now contains two shared libraries, libgdndk.so (BlackBerry Dynamics SDK JNI library) and libsbgse.so (Certicom native library). No actions are required to integrate these libraries.

FIPS upgrade

  • This release of the BlackBerry Dynamics SDK for Android has upgraded the FIPS provider to 140-3, replacing FIPS 140-2, to provide stronger, more modern security requirements. For more information and full details about FIPS 140-3 and 140-2, see NIST: Cryptographic Module Validation Program.
  • Algorithms that were restricted in FIPS 140-2 are still restricted in 140-3.
  • Certain algorithms that were allowed in 140-2 are no longer supported in 140-3, including the following (for most items below, some legacy uses are allowed; see the link provided above for details):
    • 3-key and 2-key TDEA encryption
    • 2-key Triple-DES for encryption
    • Skipjack for encryption
    • SHA-1 for digital signatures
    • RSA signatures less than 2048 bits
    • Most DSA signatures
    • ECDSA P-192 and similar that are less than 224-bit
  • Review the requirements and supported standards for FIPS 140-3 to confirm that your apps are compliant. To allow for a smooth migration to new algorithms, the BlackBerry Dynamics SDK will continue to support Triple-DES and PKCS12KDF, but you are encouraged to migrate your apps to new algorithms supported by FIPS 140-3 as soon as possible.
  • The path length constraint in the X.509 Basic Constraints extension is properly enforced.
  • If FIPS is enabled in the assigned BlackBerry Dynamics profile, when a BlackBerry Dynamics app calls an S/MIME API and uses Triple-DES for message encryption, the BlackBerry Dynamics SDK will return an error. Alternative ciphers that are supported when FIPS is enabled include AES-128-CBC and AES-256-CBC.

Security enhancements

  • This release supports authenticated encryption in SecureStorage, using AES-GCM for new BlackBerry Dynamics activations. Existing activations remain on AES-CBC.
  • The method that the SDK uses to detect changes to the device clock has been hardened to improve security.

Changes to Android software requirements

  • Minimum Gradle version: 8.11.1
  • Android Gradle Plug-in (com.android.tools.build:gradle): 8.9.1
  • The NDK version has been upgraded to 27.3.13750724

Removal of BlackBerry Protect Mobile features

As of November 2025, the following BlackBerry Protect Mobile features are no longer supported or available for use in UEM, and are no longer supported by the BlackBerry Dynamics SDK:
  • Detecting malware on Android devices
  • Safe browsing with BlackBerry Dynamics apps
  • Scanning URLs in text messages

Known issues and limitations

If you enable “Do not allow copying data from BlackBerry Dynamics apps into non-BlackBerry Dynamics apps” in a BlackBerry Dynamics profile, the “Character limit for cut and copy” allows you to specify how many characters users are permitted to copy from a BlackBerry Dynamics app to non-BlackBerry Dynamics apps. The character limit option was introduced in UEM 12.21 and requires BlackBerry Dynamics apps with SDK version 14.0 or later. Any BlackBerry Dynamics profiles that existed before the upgrade to UEM 12.21 or later will display the default value of 30 for the character limit option, but the limit is not enforced until you make a change to the profile and save it. (EMM-157418)

If a BlackBerry Dynamics app is configured for biometric authentication, when a device user force stops the app and then changes the system time or time zone, when the user restarts the app, the app does not receive the new time updates and may not provide the expected biometric authentication prompt. (GD-63799)

Play Integrity attestation will fail during app provision on an Android emulator. (GD-61278)

Users cannot upload files from Google Drive by selecting the file from the native Android file picker. (GD-60021)

If a user is activating a BlackBerry Dynamics app using a QR code and selects the "Only this time" option when prompted to grant permissions, certificate import issues might occur if the app remains in the background for longer than one minute during the import process. BlackBerry recommends that users select the "While using the app" option when prompted. (GD-54972)

Workaround: Instruct users to force close the app and open it again.

If a BlackBerry Dynamics app uses Kerberos authentication and the app tries to access a web page using an IP address, after the user enters their credentials, the web page does not load as expected and the user is prompted for their credentials again in a loop. (GD-54481)

Workaround: When developing BlackBerry Dynamics apps, do not hard code URLs that use IP addresses. If users can manually enter a URL, instruct users to avoid URLs that use an IP address.

If battery saving mode is enabled and an app tries to open a BlackBerry Dynamics app that was not already open using AppKinetics, the BlackBerry Dynamics app might not come to the foreground. (GD-54205)

Workaround: The user can start the BlackBerry Dynamics app and leave it running in the background before performing the AppKinetics operation.

If you use direct references to the BlackBerry Dynamics SDK .aar files in your build.gradle repositories (for example, implementation name:'android_handheld_platform-$DYNAMICS_SDK_VERSION', ext:'aar') instead of using Maven linkage (for example, implementation 'com.blackberry.blackberrydynamics:android_handheld_platform:$DYNAMICS_SDK_VERSION'), errors may occur in the AndroidManifest file in the Gradle caches directory. To resolve this, use Maven linkage or specify android_handheld_resources and android_handheld_platform in the build.gradle file. (GD-51938)