How to set up Pull Authorization to grant or restrict access to specific web sites on the BlackBerry Browser
Doc ID : KB10342
Last Modified : 12-02-2008
Document Type : Support
Environment
- BlackBerry® Enterprise Server software versions 4.0 and 4.1 for IBM® Lotus® Domino®
- BlackBerry® Enterprise Server software versions 4.0 and 4.1 for Microsoft® Exchange
Overview
The BlackBerry® Mobile Data Service, used in BlackBerry Enterprise Server software version 4.0, and the BlackBerry® Mobile Data System (BlackBerry® MDS) Connection Service, used in BlackBerry Enterprise Server software version 4.1, can be configured to allow or block access to specific web sites based on roles defined in the Access Control List by system administrators. A role or rule may prevent or grant access to BlackBerry smartphone users from viewing certain web sites in the BlackBerry® Browser.
To configure the pull authorization, complete the following tasks in BlackBerry Manager.
For BlackBerry Enterprise Server software version 4.0
Task 1
Create Pull Roles.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select MDS Access Control.
- Double-click Pull Roles, and then click New.
- In the Name field, type the new role name.
- In the Description field, type the role description.
- Click OK.
Task 2
Map the BlackBerry smartphone users to Pull Roles.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select MDS Access Control.
- Double-click User to Role Mapping.
- Assign the BlackBerry smartphone users to the appropriate Pull Roles.
- Click OK.
Task 3
Create Uniform Resource Locator (URL) patterns.
Note: IP Addresess cannot be used for services like HTTPS, HTTP, TCP etc.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select MDS Access Control.
- Double-click URL Patterns, and then click New.
- Complete one of the following:
- To specify all web sites, type *:*/* in the URL Pattern field.
- To specify a web domain, type *.<domain_name>.com:*/* in the URL Pattern field.
- To specify a specific web page, type www.<domain_name>.com:80/<subfolder>/webpage.htm in the URL Pattern field.
- To specify a specific web resource, type www2.<domain_name>.com:80/<subfolder>/main.gif in the URL Pattern field. Note: The asterisk character ( * ) is used as a wild card for the URL Pattern definition.
- Select the Service Name that is associated with the URL Pattern. For example, Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol over Secure Sockets Layer (HTTPS), Lightweight Directory Access Protocol (LDAP), Online Certificate Status Protocol (OCSP), or Transmission Control Protocol (TCP).
- Click OK.
Task 4
Allow or deny Pull Roles to URL Patterns.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select MDS Access Control.
- Double-click URL Pattern to Role Mapping.
- Select Allow or Deny to the Pull Roles for each URL pattern.
- Click OK.
Task 5
Turn on Pull Authorization.
- From the left pane, select the appropriate BlackBerry Enterprise Server instance.
- On the Mobile Data Services tab, click Edit Properties.
- Select Local Access Control.
- Set Pull Authorization to True.
- Click OK.
Task 6
Restart the BlackBerry Mobile Data Service.
Important: Restarting certain BlackBerry Enterprise Server services will delay email message delivery to BlackBerry smartphones. For more information, see
KB04789.
For BlackBerry Enterprise Server software version 4.1
Task 1
Create Pull Rules.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select Access Control.
- Double-click Pull Rules, and then click New.
- In the Name field, type the new rule name.
- In the Description field, type the rule description.
- Click OK.
Task 2
Map the BlackBerry smartphone users to User Rules.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select Access Control.
- Double-click User to Rules.
- Assign the BlackBerry smartphone users to the appropriate Pull Rules.
- Click OK.
Task 3
Create URL patterns.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select Access Control.
- Double-click URL Patterns, and then click New.
- Complete one of the following:
- To specify all web sites, type *:*/* in the URL Pattern field.
- To specify a web domain, type *.<domain_name>.com:*/* in the URL Pattern field.
- To specify a specific web page, type www.<domain_name>.com:80/<subfolder>/webpage.htm in the URL Pattern field.
- To specify a specific web resource, type www2.<domain_name>.com:80/<subfolder>/main.gif in the URL Pattern field. Note: The asterisk character ( * ) is used as a wild card for the URL Pattern definition.
- Select the Service Name that is associated with the URL Pattern. For example, HTTP, HTTPS, LDAP, OCSP, or TCP.
- Click OK.
Task 4
Allow or deny Pull Roles to URL Patterns.
- In the left pane, select BlackBerry Domain.
- On the Global tab, click Edit Properties.
- Select Access Control.
- Double-click URL Pattern Rules.
- Select Allow or Deny to the User Rules for each URL pattern.
- Click OK.
Task 5
Turn on Pull Authorization.
- From the left pane, select the appropriate BlackBerry Enterprise Server instance for MDS-CS.
- On the Connection Service tab, click Edit Properties.
- Select Access Control.
- Set Pull Authorization to True.
- Click OK.
Task 6
Restart the BlackBerry MDS Connection Service.
Important: Restarting certain BlackBerry Enterprise Server services will delay email message delivery to BlackBerry smartphones. For more information, see
KB04789.
Additional Information
The Pull Roles or Pull Rules can be created based on logical user groups. For example, Junior Executives, Senior Executives, and Management.