Connect BlackBerry UEM to a BlackBerry
Dynamics PKI connector
BlackBerry UEM
to a BlackBerry
Dynamics
PKI connectorIf you want to use your organization's PKI software to enroll certificates for
BlackBerry
Dynamics
apps, and your PKI software isn't supported for a direct connection with BlackBerry UEM
, you can set up a BlackBerry
Dynamics
PKI connector to communicate with your CA and link BlackBerry UEM
to the PKI connector. In a BlackBerry UEM Cloud
environment, you must have a BlackBerry Connectivity Node
installed to allow BlackBerry UEM
to communicate with the PKI connector through the BlackBerry Cloud Connector
.
A PKI connector is a set of
Java
programs and web services on a back-end server that allows BlackBerry UEM
to send certificate requests and receive responses from the CA. BlackBerry UEM
uses the BlackBerry
Dynamics
user certificate management protocol to communicate with the PKI connector. This protocol runs over HTTPS and defines JSON-formatted messages. For more information on setting up a BlackBerry
Dynamics
PKI connector, see the User Certificate Management Protocol and PKI Connector documentation.Set up a
BlackBerry
Dynamics
PKI connector.- On the menu bar, clickSettings > External integration > Certificate authority.
- ClickAdd a BlackBerry Dynamics PKI connection.
- In theConnection namefield, type a name for the connection.
- In theURLfield, type the URL of the PKI connector.
- Select one of the following options:
- Authenticate with username and password: Choose this option ifBlackBerry UEMauthenticates with theBlackBerry DynamicsPKI Connector using password-based authentication.
- Authenticate with client certificate: Choose this option ifBlackBerry UEMauthenticates with theBlackBerry DynamicsPKI Connector using certificate-based authentication.
- If you selectedAuthenticate with username and password, in theUsernameandPasswordfields, type the username and password for theBlackBerry DynamicsPKI connector.
- If you selectedAuthenticate with client certificate, clickBrowseto select and upload a certificate that is trusted by theBlackBerry DynamicsPKI Connector. In theClient certificate passwordfield, type the password for the certificate.
- In theTrusted certificate for the PKI connectorsection you can specify the certificate thatBlackBerry UEMuses to trust connections to the PKI connector, select one of the following options:
- CA certificate from BlackBerry Control TrustStore
- CA certificate: If you select this option you must click Browse to navigate to and select your organization's CA certificate.
- PKI connector server certificate: If you select this option you must click Browse to navigate to and select your organization's PKI connector server certificate.
- To test the connection, clickTest connection.
- ClickSave.