
• Serial number of the certificate
• Digital signature of the issuer
Root certificate installation
The customer root certificate is a self-signed certificate (a self-issued certificate where the
subject and issue fields contain identical DNs, and are not empty). The customer root certificate
must be installed on the IP Deskphone and stored in the IP Deskphone trusted store for the
following reasons:
• to verify the identity of the various servers that the IP Deskphone may attempt to establish
secure connections with (such as TLS and HTTPS)
• to authenticate the signatures on software and configuration files that you download onto
the IP Deskphone.
You can install a customer root certificate by using Simple Certificate Enrollment Protocol
(SCEP) or by using the configuration file (for example 12xxSIP.cfg.).
If you use SCEP, you must first configure the URL of the CA SCEP server and the domain
name, and then you can connect to the CA and download a CA root certificate to the IP
Deskphone.
• The IP Deskphone sends the GetCACert request to the SCEP-enabled interface for a CA
server.
• The IP Deskphone waits for a response. If an error is received (such as timeout or server
unreachable), the registration process ends.
• The IP Deskphone accepts the reply which contains the CA root certificate. The reply may
also include one or two Registration Authority (RA) certificates which are stored
temporarily for use during the request for a device certificate.
• If the CA root certificate is not already on the IP Deskphone, the fingerprint is computed
and displayed. The computed fingerprint is the thumbprint of the certificate (the SHA1
hash of the public key of the certificate).
• You must Accept or Reject the fingerprint.
• If the CA root certificate is rejected, the registration process ends.
• If the CA root certificate is already in the trusted store, no prompt appears.
• If the fingerprint is accepted, the CA root certificate is added to the trusted store on the
IP Deskphone.
If you use the configuration file (for example, 11xxe.cfg), you can download one or more CA
root certificates to the IP Deskphone.
• The [USER_KEYS] section is added to the configuration file (for example 12xxSIP.cfg),
where the FILENAME attribute points to the file name of a customer root certificate in
Privacy Enhanced Mail (PEM) format. The PROTOCOL attribute of the [USER_KEYS]
Root certificate installation
SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012 199
Kommentare zu diesen Handbüchern