Change a BlackBerry UEM certificate
BlackBerry UEM
certificate- Obtain a certificate signed by a trusted CA. The certificate must be in a keystore format (.pfx, .pkcs12) and must be encrypted with a supported encryption type (TripleDES‑based PKCS#12 encryption or AES‑based PKCS#12 encryption, including AES‑128 and AES‑256). The keystore file must contain only the server (leaf) certificate and any intermediate CA certificates that are required to build a complete chain to the root. Do not include the Root CA certificate in the .pfx file.
- In the management console, on the menu bar, clickSettings > Infrastructure > Server certificates.
- On theServer certificatesorBlackBerry Dynamics certificatestabs, in the section for the certificate that you want to replace, clickView details.
- ClickReplace certificate.
- ClickBrowse. Navigate to and select the certificate file.
- In theEncryption passwordorPasswordfield, type a password.
- ClickReplace.
- If you replaced any of the certificates on the Server certificates tab, restart theUEM Coreservice on all servers.
- For certificates on theBlackBerry Dynamicscertificates tab, you can clickRevert to defaultto switch back to using a self-signed certificate.
- On theBlackBerry Dynamicscertificates tab, you can clear theTrust BlackBerry UEM CAandTrust BlackBerry Dynamics CAcheck boxes if you do not need to trust the self-signed certificates. You can clear theTrust BlackBerry Dynamics CAcheck box only if you have replaced all of the certificates on theBlackBerry Dynamicscertificates tab.
- IfBlackBerry Dynamicsapps stop communicating after you change the certificates, ensure that the apps are up to date and then instruct users to reactivate the apps.