![Cambium PTP 670 Series User Manual Download Page 47](http://html.mh-extra.com/html/cambium/ptp-670-series/ptp-670-series_user-manual_485665047.webp)
Chapter 1: Product description
Wireless operation
Page 1-23
Note
Authentication is the process of verifying the identity of the remote unit that is
attempting to form a connection. Authorization is the check that takes place to confirm
that a unit with the authenticated identity is permitted to connect. For example, a
genuine unit that is not under the control of the operator might be authenticated, but
not authorized.
Negotiation of TLS RSA key size
In TLS RSA operation, the ODUs encrypt wireless traffic using the largest mutually supported
key size provided in the respective AES licenses. For example, if the Master has the 256-bit AES
license and the Slave has the 128-bit AES license, then the link may be encrypted using a key
size of 128 bits.
PTP 670 also allows a TLS Minimum Security Level to be configured; this is the smallest key
size that will be allowed in a link between Master and Slave. For example, if the Master has TLS
Minimum Security Level of 128-bit AES and the Slave has no AES license then the link cannot
be established.
In a network where all links must be encrypted, set TLS Minimum Security Level to TLS RSA
128-bit or TLS RSA 256-bit to prevent inadvertent connection of unencrypted links.
Further reading
For information about…
Refer to…
Description of Access Method
Authentication of the remote ODU
Licensing AES encryption
How to generate AES license keys
How to configure AES encryption
Configuring the Whitelist of approved
ODUs for an HCMP sector.
TLS PSK 128-bit and TLS PSK 256-bit
Wireless Encryption TLS PSK can be used with the following Access Methods:
•
Link Access
•
Link Name Access
•
Group Access
Access Method is automatically configured to Group Access in the HCMP topology.