SIP User's Manual
244
Document #: LTRT-65412
MP-11x & MP-124
6.4.4
TLS Parameters
The Transport Layer Security (TLS) parameters are described in the table below.
Table 6-23: TLS Parameters
Parameter
Description
Web/EMS: TLS Version
Defines the supported versions of SSL/TLS (Secure Socket
Layer/Transport Layer Security.
[TLSVersion]
[0]
SSL 2.0-3.0 and TLS 1.0 = SSL 2.0, SSL 3.0, and TLS
1.0 are supported (default).
[1]
When set to 0, SSL/TLS handshakes always start with SSL 2.0
and switch to TLS 1.0 if both peers support it. When set to 1,
TLS 1.0 is the only version supported; clients attempting to
contact the device using SSL 2.0 are rejected.
TLS 1.0 Only = only TLS 1.0 is used.
Note:
Web: TLS Client Re-Handshake
Interval
EMS: TLS Re Handshake Interval
For this parameter to take effect, a device reset is
required.
Defines the time interval (in minutes) between TLS Re-
Handshakes initiated by the device.
The interval range is 0 to 1,500 minutes. The default is 0 (i.e.,
no TLS Re-Handshake).
[TLSReHandshakeInterval]
Web: TLS Mutual Authentication
EMS: SIPS Require Client
Certificate
Determines the device's behavior when acting as a server for
TLS connections.
[SIPSRequireClientCertificate]
[0]
Disable = The device does not request the client
certificate (default).
[1]
Enable = The device requires receipt and verification of
the client certificate to establish the TLS connection.
For this parameter to take effect, a device reset is required.
Notes:
The SIPS certificate files can be changed using the
parameters HTTPSCertFileName and
HTTPSRootFileName.
Web/EMS: Peer Host Name
Verification Mode
Determines whether the device verifies the Subject Name of a
remote certificate when establishing TLS connections.
[PeerHostNameVerificationMode]
[0]
Disable = Disable (default).
[1]
Server Only = Verify Subject Name only when acting as
a server for the TLS connection.
[2]
When a remote certificate is received and this parameter is not
disabled, the SubjectAltName value is compared with the list of
available Proxies. If a match is found for any of the configured
Proxies, the TLS connection is established.
Server & Client = Verify Subject Name when acting as a
server or client for the TLS connection.
The comparison is performed if the SubjectAltName is either a
DNS name (DNSName) or an IP address. If no match is found
and the SubjectAltName is marked as ‘critical’, the TLS
connection is not established. If DNSName is used, the
certificate can also use wildcards (‘*’) to replace parts of the
domain name.
Summary of Contents for Media Pack MP-112
Page 1: ...Document LTRT 65412 September 2009 User s Manual Version 5 8...
Page 2: ......
Page 16: ...SIP User s Manual 16 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 24: ...SIP User s Manual 24 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 188: ...SIP User s Manual 188 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 364: ...SIP User s Manual 364 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 366: ...SIP User s Manual 366 Document LTRT 65412 MP 11x MP 124 Reader s Note...
Page 472: ...SIP User s Manual 472 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 474: ...SIP User s Manual 474 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 482: ...SIP User s Manual 482 Document LTRT 65412 MP 11x MP 124 Reader s Notes...
Page 486: ...User s Manual Version 5 8 www audiocodes com...