Skip Navigation

Change a
BlackBerry UEM
certificate

  • Obtain a certificate signed by a trusted CA. The certificate must be in a keystore format (.pfx, .pkcs12) and must be encrypted with a supported encryption type (TripleDES‑based PKCS#12 encryption or AES‑based PKCS#12 encryption, including AES‑128 and AES‑256). The keystore file must contain only the server (leaf) certificate and any intermediate CA certificates that are required to build a complete chain to the root. Do not include the Root CA certificate in the .pfx file.
  1. In the management console, on the menu bar, click
    Settings > Infrastructure > Server certificates
    .
  2. On the
    Server certificates
    or
    BlackBerry Dynamics certificates
    tabs, in the section for the certificate that you want to replace, click
    View details
    .
  3. Click
    Replace certificate
    .
  4. Click
    Browse
    . Navigate to and select the certificate file.
  5. In the
    Encryption password
    or
    Password
    field, type a password.
  6. Click
    Replace
    .
  • If you replaced any of the certificates on the Server certificates tab, restart the
    UEM Core
    service on all servers.
  • For certificates on the
    BlackBerry Dynamics
    certificates tab, you can click
    Revert to default
    to switch back to using a self-signed certificate.
  • On the
    BlackBerry Dynamics
    certificates tab, you can clear the
    Trust BlackBerry UEM CA
    and
    Trust BlackBerry Dynamics CA
    check boxes if you do not need to trust the self-signed certificates. You can clear the
    Trust BlackBerry Dynamics CA
    check box only if you have replaced all of the certificates on the
    BlackBerry Dynamics
    certificates tab.
  • If
    BlackBerry Dynamics
    apps stop communicating after you change the certificates, ensure that the apps are up to date and then instruct users to reactivate the apps.