Change a BlackBerry UEM certificate
- Review the Considerations for changing BlackBerry Dynamics certificates.
- Obtain a certificate signed by a trusted CA. The certificate must be in a keystore format (.pfx, .pkcs12) and must be encrypted with a supported encryption type (TripleDES‑based PKCS#12 encryption or AES‑based PKCS#12 encryption, including AES‑128 and AES‑256). The keystore file must contain only the server (leaf) certificate and any intermediate CA certificates that are required to build a complete chain to the root. Do not include the Root CA certificate in the .pfx file.
- In the management console, on the menu bar, click Settings > Infrastructure > Server certificates.
- On the Server certificates or BlackBerry Dynamics certificates tabs, in the section for the certificate that you want to replace, click View details.
- Click Replace certificate.
- Click Browse. Navigate to and select the certificate file.
- In the Encryption password or Password field, type a password.
- Click Replace.
- If you replaced any of the certificates on the Server certificates tab, restart the UEM Core service on all servers.
- For certificates on the BlackBerry Dynamics certificates tab, you can click Revert to default to switch back to using a self-signed certificate.
- On the BlackBerry Dynamics certificates tab, you can clear the Trust BlackBerry UEM CA and Trust BlackBerry Dynamics CA check boxes if you do not need to trust the self-signed certificates. You can clear the Trust BlackBerry Dynamics CA check box only if you have replaced all of the certificates on the BlackBerry Dynamics certificates tab.
- If BlackBerry Dynamics apps stop communicating after you change the certificates, ensure that the apps are up to date and then instruct users to reactivate the apps.