Change a BlackBerry UEM certificate

  • Review the Considerations for changing BlackBerry Dynamics certificates.
  • Obtain a certificate signed by a trusted CA. The certificate must be in a keystore format (.pfx, .pkcs12) and must be encrypted with a supported encryption type (TripleDES‑based PKCS#12 encryption or AES‑based PKCS#12 encryption, including AES‑128 and AES‑256). The keystore file must contain only the server (leaf) certificate and any intermediate CA certificates that are required to build a complete chain to the root. Do not include the Root CA certificate in the .pfx file.
  1. In the management console, on the menu bar, click Settings > Infrastructure > Server certificates.
  2. On the Server certificates or BlackBerry Dynamics certificates tabs, in the section for the certificate that you want to replace, click View details.
  3. Click Replace certificate.
  4. Click Browse. Navigate to and select the certificate file.
  5. In the Encryption password or Password field, type a password.
  6. Click Replace.
  • If you replaced any of the certificates on the Server certificates tab, restart the UEM Core service on all servers.
  • For certificates on the BlackBerry Dynamics certificates tab, you can click Revert to default to switch back to using a self-signed certificate.
  • On the BlackBerry Dynamics certificates tab, you can clear the Trust BlackBerry UEM CA and Trust BlackBerry Dynamics CA check boxes if you do not need to trust the self-signed certificates. You can clear the Trust BlackBerry Dynamics CA check box only if you have replaced all of the certificates on the BlackBerry Dynamics certificates tab.
  • If BlackBerry Dynamics apps stop communicating after you change the certificates, ensure that the apps are up to date and then instruct users to reactivate the apps.