Skip Navigation

Create a trusted connection between 
BEMS
 and 
Microsoft Exchange Server

By default, BEMS is only aware of public CA certificates. If you enable email notifications for 
BlackBerry Work
 and your organization’s 
Microsoft Exchange Server
 doesn’t use an SSL certificate issued by a trusted CA, the connection between your 
BEMS
 instance and 
Microsoft Exchange Server
 isn’t trusted. To create a trusted connection to the 
Microsoft Exchange Server
 upload the server’s SSL certificates (or the root or intermediate certificate chain) to the 
BEMS
 database. You can upload a base64-encoded or  binary-encoded file that includes one or more SSL certificates. When you upload a single file that includes multiple SSL certificates, the certificates are displayed in the dashboard and can be deleted and replaced individually as required. 
BEMS
 supports the following file extensions: .der, .cer, .pem, and .crt. For information about creating a .pem file that includes multiple certificates, visit http://support.blackberry.com/community to read article 57259.
  1. In the 
    BlackBerry Enterprise Mobility Server Dashboard
    , under 
    BEMS System Settings
    , click 
    BEMS Configuration
    .
  2. Click 
    Upload Trust Certificate
    .
  3. Click 
    Choose File
     and navigate to the location of the certificate file that you want to upload.
  4. Click 
    Add
  5. If you upload individual SSL certificates, repeat steps 3 and 4 for each additional file.