
• KEY_ALGORITHM — is the preferred key generation algorithm. The accepted value is
KEY_ALG_RSA.
• TLS_CIPHER — is the preferred TLS Cipher used for HTTPS to configure a stronger
cipher preference when available. The values are RSA_WITH_AES_128_CBC_SHA,
and RSA_WITH_AES_256_CBC_SHA. The default value is
RSA_WITH_AES_256_CBC_SHA.
• SIGN_SIP_CONFIG_FILES — overrides the file signing of files (resource files such as
the device configuration file and the dial plan) other than the Security Policy and Customer
Certificates. The values are YES and NO. The default value is NO.
- YES—Signing is required.
- NO—No authentication check is performed.
• FP_PRESENTED — allows you to accept or reject a Finger Print if the resource file is not
signed and if there are no customer certificates.
• FP_ENTERED — allows you to manually enter and accept a Finger Print value if the
resource file is not signed and if there are no customer certificates.
• SUBJ_ALT_NAME_CHECK_ENABLE — allows you to verify the Subject Alternative
Attribute in the presented certificate. Only the IPv4 IP address is supported for this
attribute. The values are YES and NO. The default value is NO.
• SECURITY_POLICY_PARAM_CHANGE — allows the IP Deskphone to enter changes
that are made to the security policy file in the security log file.
• CERT_EXPIRE — allows you to select Certificate Expiration Policy. The default value is
LOG_EXPIRE. Following are the acceptable parameter values:
- DELETE_CERT—A certificate is deleted when it expires and a security log entry is
added.
- LOG_EXPIRE—A certificate is not deleted when it expires and a security log entry
is added. Even if the certificate is not deleted, it cannot be used to authenticate a
file.
- NO_EXPIRE_LOG—A certificate is not deleted when it expires and security log
entry is not added. Even if the certificate is not deleted, it cannot be used to
authenticate a file.
• DWNLD_CFG_ACCEPT — defines how all TFTP configuration files are authenticated
when there are no customer certificates on the phone. The parameter does not come to
effect when a customer certificate installed. The default value of the parameter is
VAL_ACCEPT.
Following are the acceptable parameter values:
- VAL_ACCEPT—Unsigned and signed files are always accepted if there are no valid
customer certificates.
- VAL_MANUAL_A—If the resource file is not signed and if there are no customer
certificates, then Finger Print Display and Accept/Reject options prompt appears.
Configure the provisioning server
62 SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012
Comentarios a estos manuales