
Parameter
Set to
Notes
AUTH
1
Ensures usage of HTTPS file servers for configuration and software
files download. After AUTH is set to 1 and the device downloads the
trusted certificates, the device can only download files from an
HTTPS server. That server must have certificates that can be
validated using a trusted certificate repository.
You can change this parameter value back to 0 only by resetting the
phone to defaults.
SSH_ALLOWED
0
Keeps SSH disabled.
SCEP parameters
Configure the following Simple Certificate Enrollment Protocol (SCEP) parameters:
Parameter
Type
Default
value
Description
MYCERTURL
String
Null
Specifies the URL to access the Simple Certificate
Enrollment Protocol (SCEP) server. The device attempts
to contact the server only if this parameter is set to other
than its default value.
MYCERTCN
String
$SERIA
LNO
Specifies the Common name (CN) for SUBJECT in the
SCEP certificate request. The values can be
$SERIALNO or $MACADDR.
If the value includes the string $SERIALNO, that string
will be replaced by the phones serial number.
If the value includes the string $MACADDR, that string
will be replaced by the phones MAC address.
MYCERTDN
String
Null
Specifies the common part of SUBJECT in SCEP
certificate request. This value defines the part of
SUBJECT in a certificate request including
Organizational Unit, Organization, Location, State, and
Country that is common for requests from different
devices.
MYCERTKEYLEN
Numeric 2048
Specifies the private key length in bits to be created in
the device for a certificate enrollment. The range is from
1024 to 2048.
MYCERTRENEW
Numeric 90
Specifies the percentage used to calculate the renewal
time interval out of the device certificate’s Validity Object.
If the renewal time interval has elapsed, the phone starts
to periodically contact the SCEP server again to renew
the certificate. The range is from 1 to 99.
The phone starts using the new certificate immediately
after the renewal, even when it is in use, for all new TLS
connections. All existing connections are not broken.
Table continues…
Parameter configuration for secure installation
April 2020
Installing and Administering Avaya J100 series IP Phones in an Open SIP
environment
265