BlackBerry Dynamics SDK for iOS version 15.x

What's new in the BlackBerry Dynamics SDK for iOS version 15.1

Feature

Description

Changes to iOS software requirements

  • This release adds support for iOS 27.
  • iOS 17 is no longer supported; iOS 18 or later is required.

SwiftData integration

This release adds support for integrating SwiftData with your BlackBerry Dynamics apps for iOS.

For more information, see Integrating Apple SwiftData with your BlackBerry Dynamics app.

Control whether Siri AI can access on-screen text

When the "Do not allow screenshots" setting is enabled for iOS devices in an assigned BlackBerry Dynamics profile, the BlackBerry Dynamics SDK prevents Siri AI from accessing on-screen and selected text in BlackBerry Dynamics apps.

Security updates

  • Support for TLS 1.3 with AES-GCM suites (AES-CCM is not supported).
  • Updates to SQLite, cURL, and OpenSSL libraries.

What's new in the BlackBerry Dynamics SDK for iOS version 15.0

Changes to the SDK and software requirements:

Feature

Description

UX enhancements

Various UI elements have been updated to reflect the latest BlackBerry branding and the latest styles for iOS.

Support for new BlackBerry Dynamics profile settings

  • This release supports a BlackBerry Dynamics profile setting added in UEM version 12.23, "iOS: Do not require authentication when securely receiving a file from an authenticated Dynamics app". This setting specifies whether iOS device users need to authenticate with a BlackBerry Dynamics app when they receive a secure file transfer from another BlackBerry Dynamics app that they have already authenticated with. By default, this setting is not enabled.
  • This release supports a BlackBerry Dynamics profile setting added in UEM version 12.21, "Open files unencrypted in other selected non-Dynamics apps". This setting can be used to allow or block the transfer and opening of unencrypted files from BlackBerry Dynamics apps to selected non-BlackBerry Dynamics apps. For more information about the developer actions required to support this feature in custom BlackBerry Dynamics apps, see Allow or block file transfer to non-BlackBerry Dynamics apps.

Share text from BlackBerry Dynamics apps using the native iOS share menu

You can use the native iOS share menu to share text (for example, a URL) from a BlackBerry Dynamics app as an email message in BlackBerry Work.

OpenSSL upgrade

  • This release of the BlackBerry Dynamics SDK for iOS has been upgraded to OpenSSL 3.5.4 to enforce stronger security, access current algorithms and features, and comply with regulatory requirements.
  • OpenSSL 3.x introduces stricter flag-handling behavior. Every flag that is semantically relevant to an operation must be provided at every call site. Not providing a required flag can cause silent data corruption or signature-verification failures. For more information, see the details for GDCryptoPKCS7 in BlackBerry Dynamics SDK for iOS: Dynamics SDK Crypto C Programming Interface and the OpenSSL Documentation for PKCS7_sign. Flag combinations that callers should review include:
    • Binary (non-MIME) signature: Pass GDPKCS7_BINARY to GDPKCS7_add_signer, GDPKCS7_final, and GDPKCS7_write when signing arbitrary binary data. Without this flag, OpenSSL performs MIME CRLF canonicalization, altering the bytes that are hashed and producing an invalid signature.
    • Detached signature: Pass GDPKCS7_DETACHED | GDPKCS7_BINARY when the signed content must travel separately from the PKCS#7 structure. During verification, the original content must be provided explicitly with the indata parameter of GDPKCS7_verify. Not doing so can result in a verification error.
  • For the BlackBerry Dynamics SDK for iOS, BlackBerry Dynamics apps using BlackBerryDynamics.xcframework need to link only to GSEProvider.xcframework. Prior to this release, BlackBerry Dynamics apps linked to a combination of BlackBerryCerticom.xcframework and BlackBerryCerticomSBGSE.xcframework.

FIPS upgrade

  • This release of the BlackBerry Dynamics SDK for iOS has upgraded the FIPS provider to 140-3, replacing FIPS 140-2, to provide stronger, more modern security requirements. For more information and full details about FIPS 140-3 and 140-2, see NIST: Cryptographic Module Validation Program.
  • Algorithms that were restricted in FIPS 140-2 are still restricted in 140-3.
  • Certain algorithms that were allowed in 140-2 are no longer supported in 140-3, including the following (for most items below, some legacy uses are allowed; see the link provided above for details):
    • 3-key and 2-key TDEA encryption
    • 2-key Triple-DES for encryption
    • Skipjack for encryption
    • SHA-1 for digital signatures
    • RSA signatures less than 2048 bits
    • Most DSA signatures
    • ECDSA P-192 and similar that are less than 224-bit
  • Review the requirements and supported standards for FIPS 140-3 to confirm that your apps are compliant. To allow for a smooth migration to new algorithms, the BlackBerry Dynamics SDK will continue to support Triple-DES and PKCS12KDF, but you are encouraged to migrate your apps to new algorithms supported by FIPS 140-3 as soon as possible.
  • The path length constraint in the X.509 Basic Constraints extension is properly enforced.
  • If FIPS is enabled in the assigned BlackBerry Dynamics profile, when a BlackBerry Dynamics app calls an S/MIME API and uses Triple-DES for message encryption, the BlackBerry Dynamics SDK will return an error. Alternative ciphers that are supported when FIPS is enabled include AES-128-CBC and AES-256-CBC.

Support for Swift Package Manager

This release adds support for using the Swift Package Manager for the distribution of iOS and iPadOS library frameworks. The SDK will continue to support CocoaPods for the foreseeable future.

Support for scene-based life cycle

This release adds support for iOS apps that use a scene-based life cycle. For more information, see Support a scene-based life cycle.

Security enhancements

This release supports authenticated encryption in SecureStorage, using AES-GCM for new BlackBerry Dynamics activations. Existing activations remain on AES-CBC.

Removal of BlackBerry Protect Mobile features

As of November 2025, the following BlackBerry Protect Mobile features are no longer supported or available for use in UEM, and are no longer supported by the BlackBerry Dynamics SDK:
  • Safe browsing with BlackBerry Dynamics apps
  • Scanning URLs in text messages

Known issues and limitations

If you enable “Do not allow copying data from BlackBerry Dynamics apps into non-BlackBerry Dynamics apps” in a BlackBerry Dynamics profile, the “Character limit for cut and copy” allows you to specify how many characters users are permitted to copy from a BlackBerry Dynamics app to non-BlackBerry Dynamics apps. The character limit option was introduced in UEM 12.21 and requires BlackBerry Dynamics apps with SDK version 14.0 or later. Any BlackBerry Dynamics profiles that existed before the upgrade to UEM 12.21 or later will display the default value of 30 for the character limit option, but the limit is not enforced until you make a change to the profile and save it. (EMM-157418)

When the authentication delegate app is not on a device, other BlackBerry Dynamics apps can still be unlocked using Touch ID or Face ID when the flipping reduction feature is enabled. The other BlackBerry Dynamics apps on the device are still controlled by the BlackBerry Dynamics profile configuration, are still subject to the administrator's compliance profile configuration, and can still be locked and wiped by the administrator. If "Require password to be re-entered and disable Touch ID and Face ID" is enabled in the BlackBerry Dynamics profile, after the time period specified for this setting elapses, the user will be required to install the authentication delegate app to access any BlackBerry Dynamics apps on their device. (GD-68192)

If the "Do not allow copying data from BlackBerry Dynamics apps into non-BlackBerry Dynamics apps" option is enabled with a set character limit, when a BlackBerry Dynamics app is open in split screen or windowed apps mode on iPadOS devices, the user cannot drag and drop characters within the set limit into a non-BlackBerry Dynamics app. (GD-68070)

If you change the primary authentication delegate from a BlackBerry Dynamics app released by BlackBerry (flipping reduction enabled) to a custom BlackBerry Dynamics app, after the change, only the authentication password set in the original app is accepted, not the password set in the custom app that is now the primary authentication delegate. (GD-67647)

If a BlackBerry Dynamics app is configured for biometric authentication, when a device user force stops the app or restarts the device, then changes the system time or time zone, when the user restarts the app, the app does not receive the new time updates and may not provide the expected biometric authentication prompt.

Similarly, if the user changes the system time or time zone while the BlackBerry Dynamics app is in the background, the app does not receive the new time updates and may present the user with an unexpected biometric authentication prompt.

(GD-63799)

When using NSURLSession for NTLM authentication, if the password includes a non-ASCII character (for example, "ä"), the authentication attempt will fail. (GD-61708)

If a user provisions a BlackBerry Dynamics app using biometric authentication (Touch ID or Face ID) while the "Permit fallback to device passcode if biometric authentication fails" policy is enabled, sends the app to the background, returns the app to the foreground, and selects "Don't Allow" at the Face ID prompt, the user is forced to use the device passcode to unlock the container instead of the container password. The user could not use the container password to unlock the app when it is sent to the background and returned to the foreground again. (GD-59075)

Workaround: The user must restart the app to use the container password. To re-enable Face ID authentication to the app, the user must go to Device Settings > Face ID and Passcode > Other Apps and enable Face ID for the app.

If a BlackBerry Dynamics app uses Kerberos authentication and the app tries to access a web page using an IP address, after the user enters their credentials, the web page does not load as expected and the user is prompted to enter their credentials again in a loop. (GD-54481)

Workaround: When you develop BlackBerry Dynamics apps, do not hard code URLs that use IP addresses. If users can manually enter a URL, instruct users to avoid URLs that use an IP address.