
A
ASTRA
6700
I
SIP T
ERMINALS
FOR
MX-ONE
88
26/1531-ANF 901 14 Uen E10 2014-01-22
21.1.2 Configure
the
phones to use persistent MTLS
Copy the following certificate related files from the openssl (Enterprise
CA) to the phones’ Configuration Management path (the same place as
where the aastra.cfg is stored). When following chapter 19.5, the path
would be to /atHome.
ca.pem - public CA signing phonecert.pem
phonecert.pem - signed client certificate
private/phonekey.pem - client private key
aastra.cfg configuration
sips persistent tls:1
sip outbound support:1
sip transport protocol:4 #UDP(1),TCP(2),SIP&UDP(0),TLS(4)
sips trusted certificates:"ca.pem"
sips root and intermediate certificates:"ca.pem"
sips local certificate:"phonecert.pem"
sips private key:"phonekey.pem"
sip outbound proxy:193.10.10.10
sip outbound proxy port:5061
sip srtp mode:2 #0(SRTP disabled),1(SRTP preferred),2(SRTP
only)
dynamic sip:1
sip proxy ip:0.0.0.0
sip proxy port:0
sip registrar ip:0.0.0.0
sip registrar port:0
##start: HTTPS is no different than just using persistent TLS.
https client method:"TLS 1.0"
https user certificates: "ca.pem"
action uri
startup:"https://193.10.10.10:22223/Startup?user=$$SIPUSER-
NAME$$"
###end: HTTPS