Assign the BEMS-Connect SSL certificate to users
BEMS-Connect
SSL certificate to usersBy default,
BEMS-Connect
uses a self-signed certificate that is generated by the BEMS
installer. - Complete one of the following tasks:
- If you use the default SSL certificate generated by theBEMSinstaller,
- In theBlackBerry Enterprise Mobility Server Dashboard, underBEMS System Settings, clickSSL Certificate.
- ClickDownload SSL Certificate. By default, the BemsCert.cer file is saved to the Downloads folder.
- If you use your own SSL certificate,export the SSL certificate chain from theMicrosoftManagement Console (MMC). If you don't know which certificate chain to download, in a command prompt typenetsh http show sslcertto confirm the certificate hash, then use the MMC to locate the certificate where the certificate thumbprint is the same as the certificate hash.
- Open theMicrosoftManagement Console (MMC).
- ClickConsole Root.
- ClickFile > Add/Remove Snap-in.
- In theAvailable snap-inscolumn, clickCertificates > Add.
- In theCertificates snap-in wizard, selectComputer account. ClickNext.
- On theComputer > SelectComputer screen, selectLocal Computer. ClickFinish.
- ClickOK.
- In theMMC, expandCertificates (Local Computer) > Personal.
- Double-click the SSL certificate.
- ClickCertification Path.
- Click the root certificate. The root certificate is the first item in the Certificate hierarchy.
- ClickView Certificate.
- Click theDetailstab.
- ClickCopy to File.
- ClickNext.
- Enter name for the certificate and export it to your desktop.
- ClickSave.
- ClickFinish.
- ClickOK.
- Complete one of the following:
- InBlackBerry UEMenvironment, create a CA certificate profile for theBEMSSelf-Signed certificate, or create individual CA certificate profiles for the CA Root certificate and any CA Intermediate certificates. Assign the profiles to users or user groups. For instructions on creating a CA certificate profile and assigning it to users or user groups, see theBlackBerry UEMadministration content.
- In aGood Controlenvironment, complete the following actions:
- UnderSettings, clickServer Certificates.
- On theTrusted Authoritiestab, click the Add icon and navigate to the certificate and upload it.
- ClickApply.Good Controlautomatically distributes the CA certificate to allBlackBerry Dynamicsapps, includingBlackBerry Connect.