![Cisco TelePresence 1000 MXP Administrator'S Manual Download Page 151](http://html.mh-extra.com/html/cisco/telepresence-1000-mxp/telepresence-1000-mxp_administrators-manual_64222151.webp)
About FIPS Mode, cont...
When FIPS mode is enabled, the video system will operate
according to NIST FIPS 140-2 Level 1 requirements. This
means that only services and cryptographic algorithms that
are accepted according to this standard will be used. Options
and menu items which is not approved will be grayed out
and/or not be selectable in the menus.
Certificate management
NIST issues certificates to products that has been verified
and tested to comply with this standard, as of this writing
TANDBERG is in the process of obtaining such a certificate.
uploading HTTPS certificate for FIPS Mode
When in FIPS mode, we recommend using HTTPS for web
management instead of HTTP. HTTPS in FIPS mode requires a user
installed certificate to operate.
Be sure to enable FIPS mode first (using either the
remote control or the dataport interface, then in a secure
environment, use the HTTP protocol to install the required
certificates before doing a restart to the video system. See
the previous page on how to enable FIPS Mode.
To ensure the authenticity of an endpoint, it is recommended that the
administrator issues/obtains and installs unique certificates to each
endpoint. This is done through the Web Interface.
To install a certificate, you need:
•
HTTPS certificate ( .PEM format)
•
Private key ( .PEM format)
•
Passphrase (optional)
•
The IP Address of the video system (see Control Panel >
Diagnostics > System Information)
The software upload procedure
NOTE!
The certificate must be installed AFTER enabling FIPS mode,
using HTTP (not HTTPS) access to the codec. This must be done by
an administrator in a secure environment, since the installation of the
certificate must occur over an unsecure link (HTTP) and sensitive files
(such as the private key) are being uploaded.
1.
Start a Web-browser on your PC and type in the
IP-address
of
your video system.
2.
If the video system is setup with an IP Access Password you
must enter the password. The default IP Access Password is
TANDBERG.
3.
Go to Endpoint Configuration > Certificate Management
4.
Press
Browse
to locate the files for the HTTPS certificate and
Private Key <
.pem format
>
5.
Type in the Passphrase and press
Upload
to upload the certificate
and private key
After having uploaded the Certificate
6.
After the certificate installation, it is recommended to disable
HTTP and use only HTTPS. Go to Control Panel > Network > LAN
Settings > IP Services to disable
HTTP
(set to
Off
) and enable
HTTPS
(set to
On
).
7.
Press the
Save and Restart
button for the changes to take effect.
!
151
Cisco TelePresence MXP Series
Administrator guide
D14791.01 MXP Series Administrator Guide F90, August
2011.
Copyright © 2010-2011 Cisco Systems, Inc. All rights reserved.
www.cisco.com
Contents
Contact us
Introduction
The menu structure
The settings library
Getting started
Appendices
Appendices