BlackBerry Dynamics global properties

The following tables describe the BlackBerry Dynamics global properties that you can configure. The Restart column indicates whether changing the property requires a restart of BlackBerry UEM.

If a property is displayed in the management console but is not documented here, it is a deprecated property that is no longer in use.

Certificate Management

Property

Description

Default

Restart

Time-to-live in seconds for the keystore for individual end-users' PKCS 12 certificates

The lifespan, in seconds, of the keystore for the PKCS 12 certificates that device users can upload to sign email messages and for client authentication.

This property is read-only and cannot be changed.

86400

—

Communication

Property

Description

Default

Restart

cntmgmt.internal.port

The internal port for the container management service.

17317

Yes

cntmgmt.max.conns.above.limit

The maximum number of connections that are allowed in excess of the limit set by the cntmgmt.max.conns.persec property.

Note: Do not change this setting without consulting BlackBerry Technical Support.

3

Yes

cntmgmt.max.conns.persec

The maximum number of connections per second for container management.

Note: Do not change this setting without consulting BlackBerry Technical Support.

30

Yes

cntmgmt.max.active.sessions

The maximum number of active sessions for container management.

10000

Yes

cntmgmt.max.idle.count

The maximum number of idle connections that are permitted for container management.

Note: Do not change this setting without consulting BlackBerry Technical Support.

0

Yes

cntmgmt.max.read.throughput

The maximum number of concurrent read operations for container management.

Note: Do not change this setting without consulting BlackBerry Technical Support.

500

Yes

cntmgmt.max.write.throughput

The maximum number of concurrent write operations for container management.

Note: Do not change this setting without consulting BlackBerry Technical Support.

500

Yes

cntmgmt.ssl.external.enable

Controls whether SSL is enabled for external container management.

This property is read-only and cannot be changed.

On

—

cntmgmt.ssl.internal.enable

Controls whether SSL is enabled for internal container management.

This property is read-only and cannot be changed.

On

—

Duplicate Containers

If UEM identifies duplicate containers on devices, it schedules batch jobs to remove them. A duplicate container has the same user ID and entitlement ID (also known as the BlackBerry Dynamics App ID) as another container on the same device. When a duplicate container is removed, it is recorded in the UEM log file.

Property

Description

Default

Restart

Automatically remove older duplicate containers on same device for the user after provisioning

Specify whether UEM automatically removes duplicate containers when a new version of an app is provisioned. If this setting is selected, it takes precedence over the other Duplicate Container properties.

On

No

Enable job to automatically remove duplicate containers (on/off)

Specify whether UEM automatically schedules jobs to identify and remove duplicate containers from devices.

On

No

Inactivity timeout in seconds before duplicate container is deleted

The amount of time, in seconds, that a duplicate container must be inactive before UEM schedules a job to remove it.

259200

No

Frequency in seconds that job to remove duplicate containers will run

How often, in seconds, UEM runs a job to identify and remove duplicate containers.

86400

No

Maximum number of containers to remove in a single job

The maximum number of inactive containers that a single job can remove from devices.

100

No

Kerberos Constrained Delegation

Property

Description

Default

Restart

Use explicit UPN

Specify whether BlackBerry Dynamics apps use an explicit UPN or implicit UPN while authenticating to services integrated with Microsoft Active Directory or Exchange ActiveSync in Office 365. Your organization's Active Directory may support both options or only one of the options, depending on your environment.

Off

No

Enable KCD (gc.krb5.enabled)

Specify whether UEM supports Kerberos Constrained Delegation for BlackBerry Dynamics apps.

Off

Yes

Miscellaneous

Property

Description

Default

Restart

config.command.expiry

How long UEM waits, in seconds, before resending an unacknowledged message.

60

Yes

config.command.retry

How often, in seconds, UEM runs the task to identify and resend unacknowledged messages. If set to 0, UEM does not run the task.

900

Yes

gc.entgw.report.userinfo

Specify whether user display names are reported to the BlackBerry Dynamics NOC.

Off

No

policy.compliance.interval

How often, in minutes, UEM retrieves compliance policies for all policy sets.

1440

Yes

Purge Inactive Containers

If UEM identifies inactive containers on devices, it schedules batch jobs to remove them. UEM considers a container to be inactive if it has not connected to UEM for a default period of 90 days. When an inactive container is removed, it is recorded in the UEM log file.

Containers that have an authentication delegate configured are not purged by this process.

Property

Description

Default

Restart

Enable job to automatically remove inactive containers (on/off)

Specify whether UEM automatically schedules jobs to identify and remove inactive containers from devices.

Off

No

Container inactivity interval in seconds

The amount of time, in seconds, before UEM considers a container to be inactive.

7776000

No

Frequency in seconds that job to remove inactive containers will run

How often, in seconds, UEM runs a job to identify and remove inactive containers.

86400

No

Maximum number of containers to remove in a single job

The maximum number of inactive containers that a single job can remove from devices.

100

No

Reporting

Property

Description

Default

Restart

Set limit for records returned in exportable reports to prevent out of memory condition

The maximum number of lines that can be included in a report. The maximum value that can be entered is 1000000.

5000

No

Retention Data Policy

Property

Description

Default

Restart

gc.purge.dbJobs Purge server jobs

Specify whether UEM automatically purges server jobs at a regular interval.

On

Yes

gc.purge.dbJobs.interval Purge server jobs interval

If “Purge server jobs” is on, how often, in days, UEM purges server jobs.

30

Yes