Unify V3R3 Specifications Page 39

  • Download
  • Add to my manuals
  • Print
  • Page
    / 44
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 38
A31003-D3000-P100-01-76A9, 10-2013
OpenStage and Desk Phone IP SIP V3, Security Checklist, Planning Guide 39
Addendum
Certificate Handling
Related Topics
6.3 Certificate Handling
Certificates are used to provide authentication of connected servers and Digital
keys. Customer generated certificates must be installed on the phone.This
section gives a list of the certificates used on the phone.
In addition to installing certificates on the phone,the certificate validation policy
must be configured.
There are three levels of checking available:
The CLs for those functions which make use of certificates detail the actions
needed to setup up the certificates for that function.
Related Topics
Maximum number of erroneous login
attempts
Account lockout duration in minutes
Automatic logoff after not used period in
minutes
None There is no authentication of the server
Trusted The following is checked
that it is trusted (this means: the chain of trust for the digital signature
provided by the remote entity ends up in one of the trusted (e.g. Root CA
certificates, which are preconfigured for that interface on the phone)
that it is not expired (i.e. current date/time is within the certificate's given
validity period)
that it is not revoked (using OCSP)
Full It is assumed the server is trusted and there is no need to perform any addi-
tional checks.
The following checks additional to the “Trusted” policy:
that it has the correct identity (according to settings in altSubjectName and/
or the common name (CN) in the Subject) . This may be a FQDN, IPv4 or
IPv6 address
that it has the correct use of the following critical extension:OCSP signing.
Admin Password User Password
Page view 38
1 2 ... 34 35 36 37 38 39 40 41 42 43 44

Comments to this Manuals

No comments