
Administrator's Manual
7. Configuring Security
Version 3.4.3
161
400HD Series IP Phones
Parameter
Description
voip/media/srtp/negotiation/mode
If
voip/media/srtp/mode
=
SUPPORT_ENCRYPTION
,
t
wo SRTP negotiation modes are supported:
Basic
(default) RTP/SRTP negotiation according
to the document
IMTC Best Practices for SIP
Security
. This mode is supported by Broadsoft,
Microsoft and many other vendors
RFC5939
RTP/SRTP capability negotiation using
the attributes "a=tcap", "a=acap" and "a=pcfg" as
described in RFC 5939
voip/media/srtp/method
The SRTP encryption method.
AES_CM_128_HMAC_SHA1_32
(default)
AES_CM_128_HMAC_SHA1_80
AES_CM_128_ALL_METHODS
voip/media/srtp/use_MKI
Defines the usage of the SRTP Master Key Index.
0
= MKI is not used (default)
1
= MKI is used
voip/media/srtp/MKI_length
Defines the maximum length of the SRTP Master
Key Index. Range: 1 - 4. Default: 1.
voip/media/srtp/use_lifetime
Allows the removal of the ‘lifetime’ parameter from
the SRTP Crypto line in SDP. According to RFC
4568, an optional ‘lifetime’ parameter such as "2^31"
must be added to the a=crypto line. This parameter
allows the removal of the lifetime in all phone crypto
lines in SDP. Configurable parameter values are:
0
= the lifetime is removed
1
= the lifetime is retained (default)
voip/media/srtp/RTCP_encrypt_enabled
Default:
1
. If set to
0
,
UnencryptedSRTCP
will
present at the end of the “a=crypto” line in the SDP
offer, for example:
a=crypto:1 AES_CM_128_HMAC_SHA1_32
inline:rcO4NFj0PcKk3Pbo7IVhVqpCpQI3MWytScjR
L1IS|2^31 UNENCRYPTED_SRTCP
voip/media/srtp/RTP_encrypt_enabled
Default:
1
. If set to
0
,
UnencryptedSRTP
will
present at the end of the “a=crypto” line in the SDP
offer, for example:
a=crypto:1 AES_CM_128_HMAC_SHA1_32
inline:rcO4NFj0PcKk3Pbo7IVhVqpCpQI3MWytScjR
L1IS|2^31 UNENCRYPTED_SRTP
voip/media/srtp/RTP_auth_enabled
Default:
1
. If set to
0
,
UnauthenticatedSRTP
will
present at the end of the “a=crypto” line in the SDP
offer, for example:
a=crypto:1 AES_CM_128_HMAC_SHA1_32
inline:TDejshzv6Y04By7Add2KuZaJ9YrvteWSENcp
BMZ4|2^31 UNAUTHENTICATED_SRTP
Summary of Contents for 405HD
Page 2: ......