How to make the new iPhone work at work

Apple's new SDK, 3G handheld and iPhone 2.0 software should make it even easier to bring next-gen mobile to your enterprise. Here's what you need to know

1 2 3 Page 3
Page 3 of 3

Likewise, for Notes on the Mac, iTunes is the go-between as described for Exchange -- and you will need a separate app, such as Information Appliance Associates' PocketMac GoBetween, to make iCal and Address Book sync with Notes. Ironically, there doesn't appear to be a way to get calendar and address book data from Notes to the iPhone in Windows. If IBM follows up on its promise to ship a Notes client for iPhone, there'll be no need for a third-party app or other work-around.

You can, of course, access calendar and contact data today without connecting through the desktop by tapping Exchange or Notes Web access via the iPhone's Safari browser. Unfortunately, navigating those desktop-oriented pages even in the iPhone's fairly large screen makes this method a somewhat frustrating quick fix.

Another access issue to consider is that the Safari browser in the iPhone does not support Java or ActiveX, so Web pages that use these applet-delivery technologies won't run on the iPhone. ActiveX is a Microsoft technology available only on Windows, so the iPhone's lack of support mirrors the Mac's lack of support, but the lack of the cross-platform Java technology on the iPhone is less justifiable for Apple. (Note that it does support JavaScript.) But Sun is coming to the rescue there, promising to develop a Java virtual machine (JVM) for iPhone this spring, with a release planned for summer.

Securing the iPhone

The biggest issue for IT when it comes to the iPhone has been security, even with the availability of SSL authentication for securing e-mail connections. Make sure your Exchange or Domino server requires SSL and one of these SSL options: MD5 challenge-response, NTLM, or HTTP MD5 digest. The 1.x version of the iPhone also supports password-based SSL authentication, but that can be more easily spoofed than the other options.

Many enterprises want stronger protection than SSL provides, and so they typically use a VPN client -- or a BlackBerry or Motorola GoodLink server and its proprietary secured network -- as the conduit to safeguard all traffic with the iPhone.

The iPhone didn't originally support VPNs, but Apple added that capability via a software upgrade in late 2007. The iPhone's VPN capabilities are solid -- comparable to Windows Mobile and Palm OS devices -- with a choice of L2TP and PPTP protocols and support for EMC RSA Security's SecurID key-based authentication. (You access those through the General preference pane's Network option.)

But the iPhone 1.x VPN client does not work with all VPNs; Cisco-based VPNs in particular are incompatible unless they are set specifically for Mac OS X and iPhone compatibility. The July iPhone software update will improve VPN capabilities by supporting Cisco IPsec and two-factor authentication, certificates, and identities. The July release also adds WPA2 wireless encryption and 802.1x authentication.

Three security issues have caused the most complaints from IT, when compared with Windows Mobile, Palm OS, and BlackBerry. Apple plans to address all three in the June software update, though the details are not yet fully clear.

First, the two of those three issues -- and more. As expected, Apple will add IT-manageable security policies, and remote-kill features as part of the July update. It will also let IT control what third-party software users can download to their iPhones, download PKCS1 or PKCS2 authentication certificates to the devices, apply e-mail and other configuration options automatically to the device, and control wireless access point access through Radius policies. To do this, Apple's configuration tool generates XML profiles that can be downloaded to the iPhone via e-mail or through the built-in Safari Web browser. IT may not like the fact that the configuration utility must run on a Mac or via the Web, however.

For Exchange-managed policies, IT can use the Exchange 2003 System Manager or the Exchange 2007 Management Console.

Until July, IT will have to decide whether these three security shortfalls justify banning the iPhone from the enterprise until the new software is out and its capabilities better understood. A good way to judge that is to make an honest assessment: Are you as tough on USB thumb drives, smartphones, and work-at-home users' PCs as you want to be on the iPhone?

Correction: An earlier version of this story incorrectly reported that the new iPhone would support on-device encryption.

See more of Computerworld's iPhone 3G coverage

Related InfoWorld articles

Outfitting the iPhone for business

Executive pressure is pushing the iPhone through the side door of the enterprise, but will the CEO's crush object ever truly be business legit? Review: iPhone: The $1,975 iPod

Apple's and AT&T's high-price gadget is a heartbreaking triumph of greed over genius

Review: Supersmart phones for extreme mobility

We pick seven serious business phones with all the bells and whistles, plus the power and flexibility that real mobile professionals need

Video: Two Geeks and an iPhone: Part 1

What we use and why

Video: Two Geeks and an iPhone: Part 2

Tips and tricks for e-mail, safari, and more

Video: Two Geeks and an iPhone: Part 3

How to add third-party apps to your iPhone

Thoughts on the iPhone/iPod Touch SDK

Enterprise comes to iPhone

15 things Apple should fix in iPhone 2.0

This story, "How to make the new iPhone work at work" was originally published by InfoWorld.

Copyright © 2008 IDG Communications, Inc.

1 2 3 Page 3
Page 3 of 3
Shop Tech Products at Amazon