1-28
Cisco Unified Communications Manager Configuration Guide for the Cisco TelePresence System
OL-21851-01
Chapter 1 Configuring Cisco Unified Communications Manager for the Cisco TelePresence System
Configuring Phone Security Profile Information
Table 1-12
SIP Phone Security Profile Information Fields
Field
Required
Setting
Name
Yes
Enter a name for the security profile.
When you save the new profile, the name displays in the Device
Security Profile drop-down list box in the Phone Configuration
window for the phone type and protocol.
Tip
Include the device model and protocol in the security profile
name to help you find the correct profile when you are
searching for or updating a profile.
Description
—
Enter a description for the security profile.
Nonce Validity Time
Yes
Enter the number of minutes (in seconds) that the
nonce
value is valid.
The default value equals 600 (10 minutes). When the time expires,
Cisco Unified CM generates a new value.
Device Security Mode
Yes
Choose Encrypted from the drop-down menu (recommended).
By selecting Encrypted, Cisco Unified CM provides integrity,
authentication, and encryption for the phone. A TLS connection that
uses AES128/SHA opens for signaling, and SRTP carries the media for
all phone calls on all SRTP-capable SIP hops.
Note
The Media is Encrypted icon (closed lock) is displayed on the
screen only when the Device Security mode is set to encrypted
and cluster security mode is set to 1 (
mixed mode
).
To configure and verify cluster security mode, see the
Verifying the
Cisco Unified Communications Manager
Security Mode
section of the
Cisco TelePresence Security
Solutions Guide
.
Additional Device Security Mode field choices:
•
Non Secure—No security features except image authentication
exist for the phone. A TCP connection opens to Cisco Unified CM.
•
Authenticated—Cisco Unified CM provides integrity and
authentication for the phone. A TLS connection that uses
NULL/SHA opens.