BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 03-01-2010, 02:27 AM   #1
Neo3000
Knows Where the Search Button Is
 
Neo3000's Avatar
 
Join Date: Jul 2008
Model: 9000
PIN: N/A
Carrier: TMO
Posts: 32
Unhappy Smart way to rollout S/MIME certificates

Please Login to Remove!

Hi guys,

I am struggling with the planned roll out of S/MIME certificates in our environment.
The main issue seems to be the private key: As of KB18586, you can (1) send it by mail or (2) use desktop manager sync tool.
We do not use desktop manager, so (2) is not an option. I have a bad feeling with (1) because you transmit the private key over an insecure channel.

I tried downloading the pfx/p12 file via the browser (SSL). But that gave me an error ("The file received from the webserver was recognized as a certificate file on the device. However, the data itself was not a valid certificate. Please contact the webmaster for assistance").

I was wondering, if any of you found another smarter way of rolling out certificates ... maybe there is a tiny application doing the job out there?

If there is no other way, I will probably live with the mail option and try to transmit the p12 password to the user securely ... but still there must be a better option.

Greetings,
Neo3000
__________________
BES 4.1.7 (20 servers), Domino 7.0.3 with 19000+ users
BES 5.0.2 (8 server), Exchange 2010 SP1 with 1000+ users
Offline  
Old 03-01-2010, 09:59 AM   #2
F0nage
Thumbs Must Hurt
 
F0nage's Avatar
 
Join Date: Dec 2009
Model: 8900
PIN: N/A
Carrier: None
Posts: 96
Default

From the message you're getting I wonder if there's something wrong with the way you formatted the bundle or maybe it refuses to process a .p12/.pfx bundle with the private key included. If so, maybe you can export the cert without the private key as .p12 and then the private key as a .pem and let the user upload in 2 parts.

Last edited by F0nage; 03-01-2010 at 10:00 AM..
Offline  
Old 03-02-2010, 12:54 AM   #3
Neo3000
Knows Where the Search Button Is
 
Neo3000's Avatar
 
Join Date: Jul 2008
Model: 9000
PIN: N/A
Carrier: TMO
Posts: 32
Default

I guess you are right. Sadly, the import of p12/pfx with private key seems to be not possible via the browser. This is also stated in KB18586 if read carefully ...

But at least with 5.0 devices there is another way: I changed the MIME type for p12 on the web server to application/octet-string. The browser can not process the file and asks then if you would like to save it. If you click on "Open" then, the same certificate dialog appears as if the p12 was sent as email attachment

However with 4.5 devices this does not work: If you try to open a p12 on local storage it just says "The returned page had no content type, and therefore cannot be processed". Too bad ... on the one hand, I must change the MIME type to prohibit the processing in the browser; on the other hand, I need the correct MIME type to allow correct processing on local storage ...



Greetings,
Neo3000
__________________
BES 4.1.7 (20 servers), Domino 7.0.3 with 19000+ users
BES 5.0.2 (8 server), Exchange 2010 SP1 with 1000+ users
Offline  
Old 03-02-2010, 08:58 AM   #4
F0nage
Thumbs Must Hurt
 
F0nage's Avatar
 
Join Date: Dec 2009
Model: 8900
PIN: N/A
Carrier: None
Posts: 96
Default

Thanks for the info. I want to be able to use this on 4.6 but I don't have BES. I wonder if BESX will work.
Offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


New Original Omron CJ1W-TS561 Thermocouple Input input unit CJ1WTS561 picture

New Original Omron CJ1W-TS561 Thermocouple Input input unit CJ1WTS561

$916.00



New Allen Bradley 1762-IT4 MicroLogix Thermocouple/mV 4-Channel Input AB 1762IT4 picture

New Allen Bradley 1762-IT4 MicroLogix Thermocouple/mV 4-Channel Input AB 1762IT4

$405.00



New Factory Sealed AB 2080-TC2 2-channel Thermocouple Micro800 Plug-in Modules picture

New Factory Sealed AB 2080-TC2 2-channel Thermocouple Micro800 Plug-in Modules

$160.00



1769-IT6 Allen Bradley Compact I/O Thermocouple/mV Input Module Faakart picture

1769-IT6 Allen Bradley Compact I/O Thermocouple/mV Input Module Faakart

$720.00



K-Type Thermocouple Probe Digital Thermometer Steel Sensor Spiral Cable  picture

K-Type Thermocouple Probe Digital Thermometer Steel Sensor Spiral Cable

$10.49



EGT K-Type Thermocouple,Exhaust Probe High Temperature Sensors 1/8

EGT K-Type Thermocouple,Exhaust Probe High Temperature Sensors 1/8" NPT Threads

$12.03







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.