
3. The IP Deskphone checks the validity periods as follows:
• Not Valid Before—Not used
• Not Valid After—The IP Deskphone checks this when
- The CTL file is downloaded.
- Every 24 hours.
- When a remote certificate is presented to the IP Deskphone.
- The CTL is expired; the CTL is deleted and an event is logged in the
security log.
4. After the IP Deskphone starts a TLS channel with a server (EAP or TLS) and
receives a server certificate, the IP Deskphone validates the certificate by checking
the availability of the certificate in the CTL and to decide whether to trust the
certificate or not. If the server certificate is not in the CTL, the server certificate is
rejected and a TLS channel is not established.
The administrator has to ensure that the CTL is up-to-date. If a new CTL is downloaded to the
IP Deskphone, the old CTL file is overwritten by the new one.
The IP Deskphone can trust up to ten server certificates in the CTL file.
The following is an example of a CTL file.
Figure 29: Example of a CTL file
Validating a certificate using the Certificate Trust List
SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012 213
Comentarios a estos manuales