Welcome to Port3101.org : Your BES Connection Mark forums read | View Forum Leaders
Port3101.org : Your BES Connection



Reply
LinkBack Thread Tools Display Modes
Changing the Encryption Algorithm on the BES
 
  #1 (permalink)  
Old 05-26-2009, 03:24 PM
BES Activated
 
Join Date: May 2009
Location: Minneapolis, MN
Posts: 1
Default Changing the Encryption Algorithm on the BES

With regard to a post by Mr. E:
"KB13160 - BlackBerry Enterprise Server encryption algorithms and the impact to BlackBerry smartphone users"

The 3rd entry under the things to consider heading states:
"When changing from Triple DES encryption to Triple DES and AES encryption - BlackBerry smartphone users will be automatically be updated to AES encryption."

I would like to change the encryption algorithm from 3DES to 3DES & AES so that I can start to get the majority of my devices up to AES encryption.

The server states that:
Set the encryption algorithm to use for all BlackBerry data: Triple Data Encryption Standard (DES), Advanced Encryption Standard (AES), or both. Warnings:Changing encryption algorithms stops basic operation of the BlackBerry device. Reconnect the BlackBerry device or perform a wireless enterprise activation to send and receive messages on the BlackBerry device again.

If I change the setting to "3DES and AES", will the server require me to do wireless enterprise activations on all my devices, or is it a seamless change to the user?

Running 4.1.5.24

Any help would be greatly appreciated as I would hate to make this change and then have all my users screaming!

Regards,

Bryan
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-26-2009, 03:46 PM
BES Administrator
 
Join Date: Jan 2009
Location: Chicago
Posts: 44
Default

I was assured by RIM that changing from 3DES to 3DES+AES would gradually, automatically, in the background, upgrade all AES capable devices over 30 days as their keys expired. The devices would regenerate silently a new AES key without user intervention or reactivation.

I however did not make the change, as it was denied at the last minute due to security concerns about Chinese govt not allowing encryption over 128bits. (This was a HK BES server)

So no guarantees but do what I did and have RIM confirm this for you to cover your own butt in case the worst should happen...
Reply With Quote
  #3 (permalink)  
Old 05-26-2009, 03:47 PM
AUTiger92's Avatar
BES Expert
 
Join Date: Jan 2009
Location: Alabama
Posts: 82
Default

Should be seamless. I've done it for 4 BES Servers. The preferred encryption between Blackberry and BES is AES, so if you are at 3DES now and move to 3DES and AES the Blackberries and BES will automatically moved to AES encryption. If you have an older device that doesn't support AES it will stay at 3DES.

I saw the warning message and stop at it as well until I had spoken with RIM support.
__________________
AUTIGER92
Exchange\Blackberry Admin
4 - BES Servers (4.1.6), 3 Exchange Organizations,
~1800 BB Users, and a headache.
War Eagle!!
Reply With Quote
  #4 (permalink)  
Old 05-29-2009, 04:05 PM
Otto's Avatar
Proprietor
 
Join Date: Nov 2008
Location: Atlanta, GA
Posts: 2,032
Blog Entries: 14
Default

Your pre-4.0 devices that use 3DES will remain on 3DES, while all other devices that support AES will update to AES. You could then look into slowly migrating to AES only (provided your security department would recommend and approve this change), although you'd want to validate that no 3.x devices still exist in the environment.
__________________
BCSA (4.1, 5.0) | BCSD (4.1, 5.0)

The views expressed by me on Port3101.org are my own and do not necessarily reflect the views of my employer.
Reply With Quote
  #5 (permalink)  
Old 05-30-2009, 05:04 AM
BES Activated
 
Join Date: Jan 2009
Location: South Africa
Posts: 1
Default

Just made the change this week on a BES (4.1) with 130 users. No problem.
Reply With Quote
  #6 (permalink)  
Old 06-15-2009, 12:56 PM
BES Administrator
 
Join Date: Jan 2009
Location: Chicago
Posts: 44
Default

Thanks for the followup!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 09:06 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.


 

SEO by vBSEO 3.3.2 PL2