Blackberry Storm 2 Instruction Manual
Have a look at the manual Blackberry Storm 2 Instruction Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 57 Blackberry manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.

Turn off automatic backup and restore of key store dataBy default, items in the key store on your BlackBerry® device are backed up or restored when you back up or restore your device data. If you do not want to back up your private key to or restore your private key from your computer for security reasons, you can turn off automatic backup and restore of key store data. 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click Key Stores . 5. Change the Allow Key Store Backup/Restore field to No. 6. Press the Menu key. 7. Click Save. To turn on automatic backup and restore of key store data, change the Allow Key Store Backup/Restore field to Yes. Change the refresh rate for certificate revocation lists 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click Key Stores . 5. Change the Certificate Status Expires After field. 6. Press the Menu key. 7. Click Save. Your BlackBerry® device downloads a new revocation status automatically when your device uses a key store item with a status that is older than the time limit that you set. Reject certificate revocation lists from unverified CRL servers 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click Key Stores . 5. Change the Accept Unverified CRLs field to No. 6. Press the Menu key. 7. Click Save. Your BlackBerry® device rejects certificate revocation lists from CRL servers that the BlackBerry® MDS Connection Service cannot verify. User GuideSecurity279

Smart cards About using a smart card with your device Smart cards store certificates and private keys. You can use a smart card reader to import certificates from a smart card to the key store on your BlackBerry® device, but you cannot import private keys. As a result, private key operations such as signing and decryption use the smart card, and public key operations such as verification and encryption use the public certificates on your device. If you use a smart card certificate to authenticate with your device, after you connect your smart card reader to your device, your device requests authentication from the smart card each time that you unlock your device. You can install multiple smart card drivers on your device, including drivers for microSD smart cards, but you can only authenticate to one smart card at a time. If you are authenticating using a microSD smart card and you want to transfer media files between your microSD smart card and your computer in mass storage mode, you must temporarily turn off two-factor authentication or select a different authentication option. If the S/MIME Support Package for BlackBerry® devices is installed on your device, you can use smart card certificates to send S/MIME- protected messages. About two-factor authentication Two-factor authentication is designed to provide additional security for your BlackBerry® device. Two-factor authentication requires an item that you have (for example, a smart card) and an item that you know (for example, a pass phrase). You can also use the connection to your smart card reader to authenticate, without requiring a smart card to be present. You can use a smart card for two-factor authentication when you unlock your device, or you can use a software token for two-factor authentication when you use your device with RSA® software as a hardware token. If you have a Wi-Fi® enabled BlackBerry device, you can also use a software token for two-factor authentication when you log in to a VPN or connect to a Wi-Fi network. Depending on your BlackBerry device model and the two-factor authentication settings that you choose, you might need to type your pass phrase when you perform one of the following actions: • unlock your BlackBerry device • change a general security option on your BlackBerry device • change a smart card option • use your BlackBerry device with RSA software • log in to a VPN • connect to a Wi-Fi network Turn on two-factor authentication To perform this task, you must have set a password for your BlackBerry® device and have the smart card password that you received with your smart card. 1. On the Home screen or in a folder, click the Options icon. User GuideSecurity280

2. Click Password . 3. Perform one of the following actions: • To use a smart card and your device password to unlock your device, set the User Authenticator field to Smart Card . • To use your connected smart card reader (even if the smart card is not inserted) and your device password to unlock your device, set the User Authenticator field to Proximity . Set the Prompt for Device Password field to Yes. 4. Press the Menu key. 5. Click Save. Import a certificate from a smart card 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click Certificates . 5. Press the Menu key. 6. Click Import Smart Card Certs . 7. Type your smart card password. 8. Select the check box beside a certificate. 9. Click OK. 10. Type your key store password. 11. Click OK. Lock your device when you remove your smart card from your smart card reader 1. On the Home screen or in a folder, click the Options icon. 2. Click Password . 3. If necessary, change the User Authenticator field to Smart card . 4. Change the Lock On Card Removal field to Enabled . 5. Press the Menu key. 6. Click Save. About smart password entry If you use advanced authentication and your BlackBerry® device password or smart card password is numeric, you might be able to use smart password entry in some password fields. When smart password entry is turned on, your device is designed to remember the format of a password that you type in a password field. When you type the password again, your device applies a smart password filter to the password field. If the password is numeric, a 123 indicator appears beside the password field. If the password is alphanumeric, an ABC indicator appears beside the password field. To use smart password entry, advanced authentication must be turned on and the correct smart card driver and smart card reader must be installed on your device.User GuideSecurity281

Turn off smart password entryTo perform this task, you must be using a smart card and a password to unlock your BlackBerry® device. You can turn off smart password entry to reduce the chance that someone might guess your device password or smart card password based on the smart password filter that your device applies to password fields. 1. On the Home screen or in a folder, click the Options icon. 2. Click Password . 3. If necessary, change the User Authenticator field to Smart Card . 4. Set the Smart Password Entry field to Disabled . 5. Press the Menu key. 6. Click Save. To turn on smart password entry again, set the Smart Password Entry field to Enabled . Switch smart password filters In a blank password field, press the Enter key. The indicator for the new smart password filter appears beside the password field. Prerequisites: Using authentication certificates • Your BlackBerry® device must have the correct smart card driver and smart card reader driver installed. • You must have imported a certificate from your smart card that you can use for signing and verification. • You must turn on advanced authentication. • You must have set a device password. • You must have the smart card password that you received with your smart card. Use a certificate to authenticate your smart card To perform this task, you must be using a smart card and a password to unlock your BlackBerry® device. If you use a certificate to authenticate your smart card, the certificate authenticates your smart card whenever you use your smart card to unlock your device. 1. On the Home screen or in a folder, click the Options icon. 2. Click Password . 3. If necessary, change the User Authenticator field to Smart card . 4. Set the Authentication Certificate field. 5. Press the Menu key. 6. Click Save. To stop using a certificate to authenticate your smart card, set the Authentication Certificate field to None. User GuideSecurity282

Check the status of your authentication certificate automaticallyTo perform this task, you must be using a smart card and a password to unlock your BlackBerry® device. 1. On the Home screen or in a folder, click the Options icon. 2. Click Password . 3. If necessary, change the User Authenticator field to Smart Card . 4. Change the Certificate Status Check field. 5. Press the Menu key. 6. Click Save. If your device checks the status of your authentication certificate and finds that it is revoked or expired, your device locks. Use a certificate to encrypt the encryption keys on your device To perform this task, your BlackBerry® device must be associated with an email account that uses a BlackBerry® Enterprise Server that supports this feature. For more information, contact your administrator. If you have encryption for data in the device memory turned on and your smart card reader supports this feature, you might be able to use a certificate from the smart card to encrypt the encryption keys on your device. 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Encryption . 4. Change the Two-Factor Protection field to Enabled . 5. Press the Menu key. 6. Click Save. Store the pass phrase for your smart card in the application memory 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Smart Card . 4. Change the PIN Caching field to Enabled . 5. Press the Menu key. 6. Click Save. Your BlackBerry® device stores the pass phrase for the same length of time as it stores your key store password. Turn off notification for smart card connections 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Smart Card . User GuideSecurity283

4. Change the LED Session Indicator field to Disabled . 5. Press the Menu key. 6. Click Save. To turn on notification for smart card connections, change the LED Session Indicator field to Enabled . Software tokens About software tokens You might need a software token to log in to a VPN. You might also need a software token to connect to your organization's network using a Wi-Fi® network. A software token includes a token code that your BlackBerry® device regenerates periodically and a PIN. For more information about software tokens, contact your administrator. Change the PIN for a software token on your device 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click Software Tokens . 5. Click a software token. 6. Click Specify PIN . VPN settings Depending on the options that your administrator has set for you, this feature might not be supported. About VPN profiles A VPN profile contains the information that you require to log in to a VPN. If your organization uses a VPN to control access to its network, you might be able to log in to the VPN and access your organization's network using a Wi-Fi® network. Depending on your organization, you might have more than one VPN profile on your BlackBerry® device. For more information about VPN profiles, contact your administrator. Prerequisites: Logging in to a VPN • Your BlackBerry® device must be associated with an email account that uses a BlackBerry® Enterprise Server that supports this feature. For more information, contact your administrator. • The Wi-Fi® network that your device is connected to must support connections to a VPN. For more information, contact your administrator.User GuideSecurity284

•If you use a software token to log in to a VPN, the software token must be on your device and the software token information that appears in the VPN profile must be correct. Log in to a VPN 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click VPN. 5. Select the Enable VPN check box. 6. Click Log in. Change the user name and password for a VPN profile 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click VPN. 5. Highlight a VPN profile. 6. Press the Menu key. 7. Click Edit. 8. In the User name field, type a new user name. 9. In the User password field, type a new password. 10. Press the Menu key. 11. Click Save. Change the software token for a VPN profile To perform this task, the software token that you want to use must be installed on your BlackBerry® device. For more information, contact your administrator. 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Advanced Security Options . 4. Click VPN. 5. Highlight a VPN profile. 6. Press the Menu key. 7. Click Edit. 8. Set the Token serial number field. 9. Press the Menu key. 10. Click Save.User GuideSecurity285

About security self-testsSecurity self-tests are designed to verify that security software is implemented correctly on your BlackBerry® device. The tests should run automatically when your device restarts. Verify security software 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Information . 4. Press the Menu key. 5. Click Verify Security Software . Third-party application control About permissions for third-party applications You can set permissions that control how third-party applications on your BlackBerry® device interact with the other applications on your device. For example, you can control whether third-party applications can access data or the Internet, make calls, or use Bluetooth® connections. If you have added third-party applications to your device, the device firewall is designed to prevent these applications from sending or receiving data without your knowledge. Before a third-party application sends or receives data, a dialog box prompts you to accept or deny the connection request. If you turn off the prompt, you can reset the firewall options to receive the connection prompt again. Reset connection permissions for third-party applications 1. On the Home screen or in a folder, click the Options icon. 2. Click Security Options . 3. Click Firewall. 4. Press the Menu key. 5. Click Reset Settings . About direct Internet connections for third-party applications Some third-party applications that you add to your BlackBerry® device might require a direct TCP or HTTP connection to the Internet. For example, a stock price application might need to connect to the Internet to retrieve the latest stock prices. You might have to set the APN that the third-party application uses for this connection. User GuideSecurity286

Set up a direct Internet connection for a third-party applicationTo obtain the user name and password for the APN, contact your wireless service provider. 1. On the Home screen or in a folder, click the Options icon. 2. Click Advanced Options . 3. Click TCP. 4. Type the APN information. 5. Press the Menu key. 6. Click Save. Turn on safe mode When you start your BlackBerry® device, you can turn on safe mode to prevent third-party applications from running automatically. This safe mode enables you to troubleshoot or remove any unwanted applications. 1. Remove and reinsert the battery. 2. When the red LED light goes out, press and hold the Escape key as the device is loading. 3. When the dialog appears, click OK. When safe mode is on, a safe mode indicator appears in the device status section of the Home screen. To turn off safe mode, repeat step 1. Set permissions for a third-party application Note: Changing permissions for third-party applications can significantly affect the operation of applications on your BlackBerry® device. For more information about how changing these permissions might affect the operation of the applications on your device, contact your wireless service provider or administrator. 1. On the Home screen or in a folder, click the Options icon. 2. Click Advanced Options . 3. Click Applications . 4. Highlight a third-party application. 5. Press the Menu key. 6. Perform one of the following actions: • To set permissions for the highlighted third-party application, click Edit Permissions. • To set permissions for all third-party applications, click Edit Default Permissions. 7. Expand Connections , Interactions , or User Data . 8. Change the permission fields. 9. Press the Menu key. 10. Click Save. User GuideSecurity287

Connection permissions for third-party applicationsUSB: Set whether third-party applications can use physical connections, such as a USB cable or RS-232 cable, that you have set up for your BlackBerry® device. Bluetooth: Set whether third-party applications can use Bluetooth® connections. Phone: Set whether third-party applications can make calls or access call logs. Location Data: Set whether third-party applications can use your GPS location information. Server Network: Set whether third-party applications can access the Internet or your organization's intranet using your organization's network. Internet: Set whether third-party applications can access the Internet through your wireless service provider (for example, using a direct Internet connection or a WAP gateway). Wi-Fi: Set whether third-party applications can use Wi-Fi® connections. Interaction permissions for third-party applications Cross Application Communication: Specify whether third-party applications can communicate and share data with other applications on your BlackBerry® device. Device Settings: Specify whether third-party applications can turn on or turn off your device or change device options, such as display options. Media: Specify whether third-party applications can access media files on your device. Application Management: Specify whether third-party applications can add or delete application modules or access module information such as an application name or version. Themes: Specify whether your device can use third-party applications as a source for customized themes. User GuideSecurity288