
Supplemental Guide – DOC. 8412A
UC-P100-S/UC-P110-S Phones for Skype for Business
•
333
•
Server Certificate: When clients request a TLS connection with the Skype for
Business phone, the Skype for Business phone sends the server certificate to the
clients for authentication. The Skype for Business phone has two types of built-in
server certificates: a unique server certificate and a generic server certificate.
Only one server certificate can be uploaded to the Skype for Business phone. The
old server certificate will be overridden by the new one. The format of the server
certificate files must be *.pem and *.cer and the maximum file size is 5MB.
−
A unique server certificate: It is unique to a Skype for Business phone (based
on the MAC address) and issued by the Certificate Authority (CA).
−
A generic server certificate: It is issued by the Certificate Authority (CA). Only
if no unique certificate exists, the Skype for Business phone may send a
generic certificate for authentication.
The Skype for Business phone can authenticate the server certificate based on the
trusted certificates list. The trusted certificates list and the server certificates list
contain the default and custom certificates. The type of certificates the Skype for
Business phone accepts can be specified: default certificates, custom certificates, or all
certificates.
The Common Name Validation feature enables the phone to require validation of the
common name of the certificate sent by the connecting server. The Security verification
rules are compliant with RFC 2818.
NOTES:
•
In the TLS feature, we use the terms “trusted” and “server” certificates. These
are also known as CA and device certificates.
•
Resetting the Skype for Business phone to factory defaults will delete custom
certificates by default. This feature is configurable by the parameter
“static.phone_setting.reserve_certs_enable” using the configuration files.
Configuration changes can be performed using the configuration files or locally.
Configuration Methods
Central Provisioning
(Configuration File)
<y0000000000xx>.cfg
Configure the trusted certificates feature.
Parameters:
static.security.trust_certificates
static.security.ca_cert
static.security.cn_validation
Configure the server certificates feature.
Parameters:
static.security.dev_cert
Upload the trusted certificates.
Parameter:
static.trusted_certificates.url