Configuring Secure SRST for SCCP and SIP
Information About Configuring Secure SRST
183
Cisco Unified SCCP and SIP SRST System Administrator Guide
OL-13143-04
Figure 1
Interworking of Credentials Server on SRST Router, Cisco Unified Communications
Manager, and Cisco Unified IP Phone
Table 2
Establishing Secure SRST
Mode
Process
Description or Detail
Regular Mode The Cisco Unified IP Phone configures DHCP and
gets the TFTP server address.
—
The Cisco Unified IP Phone retrieves a CTL file
from the TFTP server.
The CTL file contains the certificates that the phone
should trust.
The Cisco IP Phone opens a Transport Layer
Security (TLS) protocol channel and registers to
Cisco Unified Communications Manager.
Cisco Unified Communications Manager exports
secure Cisco Unified SRST router information and
the Cisco Unified SRST router certificate to the Cisco
Unified IP phone. The phone places the certificate
into its configuration. Once the phone has the Cisco
Unified SRST certificate, the Cisco Unified SRST
router is considered secure. See
Figure 1
.
If the Cisco Unified IP Phone is configured as
“authenticated” or “encrypted” and Cisco
Unified Communications Manager is configured
in mixed mode, the phone looks for an SRST
certificate in its configuration file. If it finds an
SRST certificate, it opens a standby TLS
connection to the default port. The default port is
the Cisco Unified IP Phone TCP port plus 443;
that is, port 2443 on a Cisco Unified SRST router.
The connection to the SRST router happens
automatically, assuming there is not a secondary
Cisco Unified Communications Manager and Cisco
Unified SRST is configured as the backup device. See
Figure 1
.
Cisco Unified Communications Manager should be
configured in mixed mode, which is its secure mode.
In case of WAN failure, the Cisco Unified IP Phone starts Cisco Unified SRST registration.
SRST Mode
The Cisco Unified IP Phone registers with the
SRST router at the default port for secure
communications.
—
155100
Cisco Unified
Communications
Manager/client
Cisco IP phone
Credentials server
running on secure
Cisco Unified
SRST router
2. The credentials server responds
with the certificate.
3. Cisco Unified Communications Manager inserts
the certificate in the phone configuration file.
IP
WAN
1. Cisco Unified Communications Manager
requests the Cisco Unified SRST certificate
from the credentials server.