Avaya SIP Software 3.2 for 1200 Series Manual de usuario Pagina 201

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 320
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 200
1. Server can provide only its Server certificate.
2. Server can provide the entire certificate chain (up to the Root CA certificate).
In the first scenario, the IP Deskphone only needs the CA certificate which was used to sign
the Server certificate. The certificate file must be PEM encoded.
In the second scenario, every certificate in the chain must be verified. Root and Intermediate
CA certificates of the chain must be installed in the IP Deskphone Trusted Certificates store.
Certificates must be PEM encoded and combined into one file.
Device certificate installation
A device certificate is a certificate used to prove the identity of the IP Deskphone to a server
while establishing various secure connections, such as TLS and HTTPS, between the
IP Deskphone and a server. Each device certificate is associated with a specific usage
purpose. It is possible for one or two device certificates to be installed on the IP Deskphone
(for example, one for all TLS connections and one for VPN). A Device Certificate Profile (DCP)
allows for various combinations of sharing device certificates among different applications.
Within the DCP, you can identify one of more uses (or purposes) for the device certificate
associated with each profile, to provide a flexible model for the sharing of device certificates
among IP Deskphone applications.
The following sections describe the process used to install a device certificate on the
IP Deskphone. This process starts with defining a DCP for each device certificate that must
be installed on the IP Deskphone. See
Device certificate profiles on page 202.
The two methods used to install a device certificate on the IP Deskphone are:
• SCEP
• PKCS#12 download
SCEP is a protocol that allows the IP Deskphone to send a device certificate request to a CA
server based on a locally generated private key to provide more security for the private key
(because the private key is never transmitted, even in an encrypted form). See
SCEP on
page 207
PKCS#12 is an industry standard for exchanging certificate and private keys. A device
certificatd downloaded to the IP Deskphone in a PKCS#12 file contains the complete certificate
including the private key of the device certificate which is generated offline by a Certificate
Authority (CA). The PKCS#12 file is encrypted using password at the time of generation to
protect the private key. See
PKCS 12 download on page 209.
For more information on defining a device certificate profile, see
Device certificate profiles on
page 202.
Device certificate installation
SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012 201
Vista de pagina 200
1 2 ... 196 197 198 199 200 201 202 203 204 205 206 ... 319 320

Comentarios a estos manuales

Sin comentarios