
Security policy file updates
The security policy file contains a set of rules for certificate-based authentication on the
IP
Deskphone. The rules include the following:
• CERT_ADMIN_UI_ENABLE — determines if the Certificate Administration user interface
is enabled on the IP Deskphone. The acceptable values are YES and NO; the default
value is NO.
• SECURITY_LOG_UI_ENABLE — determines if the Security Log user interface is
enabled on the IP Deskphone. The acceptable values are YES and NO; the default value
is NO.
• KEY_SIZE — The default size used when generating keys on the IP Deskphone. Acts as
the minimum allowed key size that should be enforced when loading certificates from the
IP Deskphone. The acceptable values are:
- KEY_SIZE_1024
- KEY_SIZE_1536
- KEY_SIZE_2048
The default value is KEY_SIZE_1024.
• KEY_ALGORITHM — The preferred key generation algorithm. The acceptable value is:
- KEY_ALG_RSA
• DWNLD_CFG_SIGNING — defines if configuration files are forced to be signed when a
customer certificate is installed.
- NO - automatically accept the downloaded file without authentication
- YES - file must be signed and fully authenticated
The default is NO.
• CUST_CERT_ACCEPT_VAL_NO_CHECK — is added to the existing values
(VAL_NO_MANUAL, VAL_MANUAL_A, VAL_MANUAL_B.
The default value is VAL_MANUAL_A).
• SEC_POLICY_ACCEPT — is for Security Policy File acceptance ( VAL_MANUAL_A,
VAL_MANUAL_B.
The default value is VAL_MANUAL_A)
• SIGN_SIP_CONFIG_FILES — overrides the file signing of a file, such as the device
configuration file and the dial plan file. You cannot override the file signing of the Security
Policy and Customer Certificates. The acceptable values are:
- YES—Signing is required.
- NO—No authentication check is performed.
Certificate-based authentication
224 SIP Software for Avaya 1200 Series IP Deskphones-Administration November 2012
Comentários a estes Manuais