Avaya SIP Software 3.2 for 1200 Series Manual de usuario Pagina 200

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 320
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 199
section can be assigned to one of the IP Deskphone supported protocols, such as HTTP,
TFTP, HTTPS and FTP.
• After the configuration file is downloaded and parsed by the IP Deskphone, the
[USER_KEYS] section is processed and the root certificate is downloaded to the IP
Deskphone.
After the certificate file is downloaded, you must authenticate the contents of the certificate
file before installing it on the IP Deskphone. There are two possible situations.
- If there are no existing customer root certificates on the IP Deskphone, a fingerprint
for the file is computed. Depending on the value that is configured in the Security
Policy parameter, CUST_CERT_ACCEPT, the user can either be prompted to
accept this fingerprint, or prompted to enter the fingerprint for verification.
- If there is one or more customer root certificate on the IP Deskphone, the certificate
file must be digitally signed with a signing certificate. In this case, there is no
interaction with the user. The signature is internally verified and the signing certificate
is verified to be issued by a customer root certificate that is already installed on the
IP Deskphone.
• If the authentication of the file is successful, the customer root certificate is installed on
the IP Deskphone in the trusted certificate store.
Important:
Although the certificate file usually contains a single customer root certificate, it is possible
that the certificate file may contain more than one certificate and CRL. This occurs where
the PEM encoding for each certificate or CRL is appended in the file with a blank line
between each file. If the authenticity of the file is successfully verified, all entities in the file
are installed on the IP Deskphone.
Signing a resource file
The following is the command to sign a resource file using openssl .
openssl smime –sign –in unsigned_file –signer sign_cert_file –outform
PEM –binary –inkey sign_cert_pk_file –out tmp_signature_file
The first customer root certificate must either be signed by a Avaya Trusted Certificate or
Fingerprint accepted. To control further signing of a customer root certificate, and prevent
security risks, the following Security Policy parameter must be configured.
CUST_CERT_ACCEPT — VAL_NO_CHECK
When the IP Deskphone tries to establish a secure connection (for example, HTTPS, SIP TLS)
with a server, the server provides its certificate which then must be verified by the IP
Deskphone.
The following are the possible configurations (depending on the server configuration):
Certificate-based authentication
200 SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012
Vista de pagina 199
1 2 ... 195 196 197 198 199 200 201 202 203 204 205 ... 319 320

Comentarios a estos manuales

Sin comentarios