BlackBerry Enterprise Service version.2 preinstallation and preupgrade checklist Verify that the following requirements are met before you install or upgrade to BlackBerry Enterprise Service version.2. Note: For more information about planning your installation or upgrade, hardware requirements, installation and upgrade instructions, and post-installation and post-upgrade tasks, visit www.blackberry.com/go/serverdocs to read the BlackBerry Enterprise Service Installation Guide or the BlackBerry Enterprise Service Upgrade Guide. Supported upgrade environments You can use the setup application to upgrade to BlackBerry Enterprise Service version.2 from BlackBerry Enterprise Service version.2 and later. 1. Verify the system requirements Company directory One of the following: Microsoft Active Directory and users with Microsoft Active Directory accounts LDAP with anonymous authentication or simple bind authentication, with or without SSL. User account information is obtained from the company directory. This information is required to create user accounts. BlackBerry Enterprise Service supports Microsoft Active Directory and LDAP connectivity to your company directory. Mobile operating system Any of the mobile operating systems listed in the BlackBerry Enterprise Service Compatibility Matrix DNS DNS support for resolving IP addresses into host names VPN hardware (optional) IPSec VPN hardware or SSL VPN hardware BlackBerry Enterprise Service supports BlackBerry devices, BlackBerry PlayBook tablets, ios devices, and Android devices. BlackBerry Enterprise Service can connect to BlackBerry Enterprise Server 5.0 SP3 or 5.0 SP4 to manage devices that run BlackBerry 7.1 and earlier. BlackBerry Enterprise Service uses DNS to resolve the IP address when it tries to connect to <country>.srp.blackberry.com. If your organization's environment includes VPNs, you can configure a device to authenticate with a VPN so that it can access your organization's network. Devices can use the BlackBerry Infrastructure if a VPN or work Wi-Fi connection is not available. all-123 1
For more information, visit www.blackberry.com/go/kbhelp/ to read article KB28128. Exchange ActiveSync Exchange ActiveSync must be enabled on your organization's messaging server to use the native email, calendar, and contacts apps on your device. For minimum requirements, refer to the BlackBerry Enterprise Service Compatibility Matrix. Exchange ActiveSync gatekeeping (optional) Microsoft Exchange Server 20 Windows PowerShell 2.0 or later installed on the computer that hosts the core components Support for Secure Work Space (optional) If you want to enable Exchange ActiveSync gatekeeping in your organization, you can configure BlackBerry Enterprise Service to support this feature and control which devices are added to an allowed list in Microsoft Exchange. You can configure Secure Work Space for ios and Android devices. Any of the mail servers listed in the BlackBerry Enterprise Service Compatibility Matrix 2. Verify the software requirements for the BlackBerry Enterprise Service core components The following requirements apply when you install all BlackBerry Enterprise Service components on one computer, or when you install the core components on a separate computer. Operating system Any of the operating systems listed in the BlackBerry Enterprise Service Compatibility Matrix Software framework All of the following: Microsoft.NET Framework 3.5 SP1; installed by the BlackBerry Enterprise Service setup application Microsoft.NET Framework 4 (Standalone Installer or Web These are the minimum software requirements to install and run the Windows services and web services for the BlackBerry Enterprise Service core components. These are the minimum software requirements to install and run the Windows services and web services for the BlackBerry Enterprise Service core components. Note: Install the full Microsoft.NET Framework 4 instead of Microsoft.NET Framework 4 Client Profile. If you plan to install the BlackBerry Collaboration Service on the same computer as the core components, install Microsoft Unified 2 all-123
Installer); requires manual installation Web server Any of the web servers listed in the BlackBerry Enterprise Service Compatibility Matrix Communications Managed API 2.0 Core Redistributable 64-bit before you install Microsoft.NET Framework 4. For more information, visit www.support.microsoft.com to read article 2224981. BlackBerry Enterprise Service uses Microsoft IIS to create websites for the Universal Device Service components to communicate with each other. Note: For Microsoft IIS, the following role services must be installed: Application Development: ASP.NET, NET Extensibility, ISAPI Extensions, ISAPI Filters Management Tools: IIS Management Console, IIS Management Scripts and Tools, Management Service, IIS 6 Management Compatibility (all subcomponents) 3. Verify the software requirements for the BlackBerry Enterprise Service consoles, if installed separately The following requirements apply if you are installing the BlackBerry Enterprise Service consoles on a separate computer. Operating system Any of the operating systems listed in the BlackBerry Enterprise Service Compatibility Matrix Software framework Microsoft.NET Framework 3.5 SP1; installed by the BlackBerry Enterprise Service setup application These are the minimum software requirements to install and run the BlackBerry Enterprise Service consoles. These are the minimum software requirements to install and run the BlackBerry Enterprise Service consoles. 4. Verify the software requirements for a remote BlackBerry Router The following requirements apply to the computer that you want to install a standalone BlackBerry Router on. The BlackBerry Router is an optional component. If you do not install the BlackBerry Router, you can connect the BlackBerry Device Service to an existing standalone BlackBerry Router in your organization's environment. You can use a standalone BlackBerry Router that you installed with BlackBerry Enterprise Server 5.0 SP4 or BlackBerry Device Service 6.2. Operating system These are the minimum software requirements to install and run the BlackBerry Router. all-123 3
Any of the operating systems listed in the BlackBerry Enterprise Service Compatibility Matrix 5. Verify the software requirements for the database server Database management system Any of the database management systems listed in the BlackBerry Enterprise Service Compatibility Matrix Collation settings To configure collation settings, the following conditions: Database server collation configured to default caseinsensitive BlackBerry Enterprise Service databases collation configured to default case-insensitive Database connectivity If the databases are installed on a separate computer, TCP/IP network protocols turned on No count option turned off Nested triggers Nested triggers support turned on. Database mirroring To configure database mirroring, the following conditions: A version of Microsoft SQL Server that supports database mirroring These are the minimum database management system requirements to host the BlackBerry Enterprise Service databases. Collation settings are used to specify how Microsoft SQL Server sorts and compares data. It is important to specify collation settings as caseinsensitive, because case-sensitive collation settings could cause incorrect search results when you search for users. Note: Most Microsoft SQL Server instances are installed with the suggested default collation settings. Default collations are suggested but non-default collations are supported (for more information, visit www.blackberry.com/go/kbhelp to read articles KB04785 and KB15534). Enabling TCP/IP allows database clients to access the Microsoft SQL Server instance. If you do not enable TCP/IP, the BlackBerry Device Service setup application cannot contact the Microsoft SQL Server instance. You can enable or disable the TCP/IP protocols in the SQL Server Configuration Manager. Note: TCP/IP is enabled by default on most Microsoft SQL Server instances. Enabling nested triggers support allows triggers to perform actions that initiate other triggers. For more information, visit msdn.microsoft.com to read article ms1781. You can configure high availability for the BlackBerry Enterprise Service databases using database mirroring. For more information about configuring high availability, visit www.blackberry.com/go/serverdocs to read the BlackBerry Enterprise Service Configuration Guide. 4 all-123
High-safety mode with automatic failover A witness server for automatic failover A mirror database on a different computer than the principal database The same version and edition of Microsoft SQL Server to host the mirror database and the principal database Use static port number 1433 only Do not use named instances 6. Verify the software requirements for the browser On computers where the BlackBerry Enterprise Service consoles are accessed, any of the browsers listed in the BlackBerry Enterprise Service Compatibility Matrix These are the browser requirements for accessing the BlackBerry Enterprise Service consoles. Note: If users use a wired connection to activate or manage their BlackBerry devices, they must use Windows Internet Explorer and allow incoming TCP/IP connections to RIMProxy.exe. The default port number for RIMProxy.exe is 5666. To support browser access, you must configure the following settings: Support for JavaScript Cookies turned on Support for TLS or SSL The SSL certificate is installed to permit trusted connections to the consoles Browser settings for Windows Internet Explorer: The latest Microsoft hotfixes installed Language preferences that display encoded web pages To support Microsoft ActiveX, the following settings are enabled: These are the required browser settings for Windows Internet Explorer. Automatic prompting for Microsoft ActiveX controls Download signed Microsoft ActiveX controls Run Microsoft ActiveX controls and plug-ins Script Microsoft ActiveX controls marked safe for scripting all-123 5
The console websites are assigned to the trusted websites security zone If you configure single sign-on authentication for the consoles, Enable Integrated Windows Authentication is selected Note: If Windows Internet Explorer Enhanced Security Configuration is turned on, some areas of the Universal Device Service console might not function correctly. 7. Other installation considerations Considerations Virtual environment Current in-market releases of VMware and Microsoft Hyper-V are supported with the latest BlackBerry Enterprise Service version. For more information, visit www.blackberry.com/go/kbhelp to read article KB29661. IP BlackBerry Enterprise Service components support only IPv4 for TCP/IP connections. Installation on a computer that hosts BlackBerry Enterprise Server 5.0 BlackBerry Enterprise Service can be installed on a computer that already hosts BlackBerry Enterprise Server 5.0 SP4 or BlackBerry Enterprise Server Express 5.0 SP4. You cannot connect BlackBerry Enterprise Service and the BlackBerry Enterprise Server or BlackBerry Enterprise Server Express to the same databases. To run BlackBerry Enterprise Service and the BlackBerry Enterprise Server or BlackBerry Enterprise Server Express in the same organization, you can configure the BlackBerry Enterprise Service databases for the BlackBerry Enterprise Service instances, and a BlackBerry Configuration Database for the BlackBerry Enterprise Server instances or BlackBerry Enterprise Server Express instances. Remote access Administrators who use Remote Desktop Connection can access BlackBerry Enterprise Service remotely. Importing SSL certificates The setup application generates and stores an SSL certificate in two password-protected keystore files: as.web.keystore and ncc.web.keystore. Several components use the SSL certificate to authenticate with browsers. You can use the BES Configuration Tool to change the password for the web keystores or to import a new SSL certificate. BlackBerry Enterprise Service does not support importing certificates into the keystores manually. 6 all-123
Considerations DMZ BlackBerry Enterprise Service components, except for BlackBerry Router, do not support installation in a DMZ. 7 all-123
BlackBerry Enterprise Service version.2 preinstallation and preupgrade tasks Complete the following tasks before you install or upgrade to BlackBerry Enterprise Service version.2. Note: For more information about preinstallation tasks, visit www.blackberry.com/go/serverdocs to read the BlackBerry Enterprise Service Installation Guide. For more information about preupgrade tasks, visit www.blackberry.com/go/ serverdocs to read the BlackBerry Enterprise Service Upgrade Guide. Create a service account with the following options set: Password that does not change or expire Part of the administrator group on the computer that you are installing BlackBerry Enterprise Service on Ability to log on locally, as a service, and as a batch job on the computer that you are installing BlackBerry Enterprise Service on (these permissions are part of the Local Security Policy) For upgrades, verify that the service account that you use to upgrade is the same account that you used to install the previous version of BlackBerry Enterprise Service. Optionally, manually register ASP.NET for use with Microsoft IIS. Optionally, enable basic authentication for Microsoft Exchange and configure a Microsoft Exchange account that has the ms-exch-epi-impersonation permission enabled. Remove the WebDAV Publishing role service. The service account is used to run the BlackBerry Enterprise Service services and can connect to the BlackBerry Enterprise Service databases. If Microsoft IIS is already installed on the computer, you must manually register ASP.NET for use with Microsoft IIS so that the Core Module and Communication Module can manage ios and Android devices. If your organization has ios devices and Android devices that have a work space enabled, configure these permissions to allow Microsoft Exchange Impersonation of all users on the Microsoft Exchange Server so that BlackBerry Enterprise Service can request and receive notifications from Microsoft Exchange when new or updated items are available in a user mailbox. If Microsoft IIS is already installed on the computer that you install BlackBerry Enterprise Service on, you must remove the WebDAV Publishing role service. 8 all-123
Remove WebDAV to avoid potential issues with updates that the setup application and the Universal Device Service perform (for example, WebDAV might cause issues when you create a username and password for the Universal Device Service console during the installation process). For upgrades, back up the BlackBerry Enterprise Service databases so that you can restore them if the upgrade process does not complete. If a database upgrade is required, the setup application automatically backs up the databases as part of the upgrade process. You can also use the backup and restore tools that are a part of Microsoft SQL Server to back up the BlackBerry Enterprise Service databases. For upgrades, back up the shared network folder. The shared network folder contains the application files and certificates that the BlackBerry Administration Service uses. Optionally, depending on the database option and the type of authentication that you select during the installation process, you might need to assign database creator permissions to the service account or the Microsoft SQL Server account. You can configure database permissions using Microsoft SQL Server roles. For upgrades, assign database creator permissions to the account that BlackBerry Enterprise Service uses to connect to the BlackBerry Enterprise Service databases. You can use the setup application to create the BlackBerry Enterprise Service databases. BlackBerry Enterprise Service uses the login information that you specify during the installation process (Windows authentication or Microsoft SQL Server authentication) to create or connect to the BlackBerry Enterprise Service databases. Optionally, use the CreateDB executable to create or upgrade the BlackBerry Enterprise Service databases on the database server. Configure ports for the external firewall. For information about configuring ports, see the BlackBerry Enterprise Service Installation Guide. If your organization's security policies do not allow applications to have permissions to create or upgrade databases, run the CreateDB executable. To permit BlackBerry Enterprise Service to access the BlackBerry Infrastructure and the Internet, you must make sure the appropriate ports are open in your organization's firewall: Port 31 for access to the BlackBerry Infrastructure Port 443 for access to the licensing infrastructure, blackberry.com, and the Apple Root Certification Authority all-123 9
Port 80 for access to the Apple Root Certification Authority Optionally, to set up a BlackBerry Administration Service pool using DNS round robin, you need: DNS records for the BlackBerry Administration Service pool name that contain the IP address of each computer that hosts a BlackBerry Administration Service instance (include only computers that host a BlackBerry Administration Service instance) A static IP address for each computer that you want to install a BlackBerry Administration Service instance on On the DNS server, in the forward lookup zone, for each BlackBerry Administration Service instance, a new host with the IP address of the computer you are installing the BlackBerry Administration Service instance on, and the Create associated pointer (PTR) record check box selected. Optionally, to set up a BlackBerry Administration Service pool using a hardware load balancer, configure session persistence for SSL connections. The DNS pool name allows browsers to access available BlackBerry Administration Service instances using a single DNS name. When you install the BlackBerry Enterprise Service administration consoles, you install a BlackBerry Administration Service instance. Session persistence is used to manage connections between the administrator's browser sessions and each BlackBerry Administration Service instance using a load balancer. Session persistence directs an SSL session consistently to the same server and preserves the session ID established with an SSL connection. 2015 BlackBerry. All rights reserved. BlackBerry and related trademarks, names and logos are the property of BlackBerry Limited and are registered and/or used in the U.S. and countries around the world. Android is a trademark of Google Inc. Apple is a trademark of Apple Inc. ios is a trademark of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. ios is used under license by Apple Inc. JavaScript is a trademark of Oracle and/or its affiliates. Microsoft, Active Directory, ActiveSync, ActiveX, Hyper-V, Internet Explorer, SQL Server, Windows, Windows PowerShell, and Windows Server are trademarks of Microsoft Corporation. VMware is a trademark of VMware, Inc. Wi-Fi is a trademark of the Wi-Fi Alliance. All other trademarks are the property of their respective owners. This documentation is provided "as is" and without condition, endorsement, guarantee, representation or warranty, or liability of any kind by BlackBerry Limited and its affiliated companies, all of which are expressly disclaimed to the maximum extent permitted by applicable law in your jurisdiction. all-123