
Mitel 6800 Series SIP Phone Release 4.2.0 SP2 Administrator Guide
6-21
TRANSPORT LAYER SECURITY (TLS)
The IP Phones support a transport protocol called
Transport Layer Security (TLS)
and
Persistent TLS
. TLS is a protocol that ensures communication privacy between the SIP phones
and the Internet. TLS ensures that no third party may eavesdrop or tamper with any message.
The 6800 Series SIP phones support TLS versions 1.0, 1.1, and 1.2. TLS 1.1 and 1.2 introduce
added security enhancements including (in TLS 1.2) the use of SHA-2 cryptographic hash
functions. When TLS is being used for SIP messages the phone will always negotiate the
highest possible TLS version in the handshaking process.
TLS is composed of two layers: the TLS Record Protocol and the TLS handshake protocol.
The TLS Record Protocol provides connection security with some encryption method such as
the Data Encryption Standard (DES). The TLS Handshake Protocol allows the server and client
to authenticate each other and to negotiate an encryption algorithm and cryptographic keys
before data is exchanged. TLS requires the use of the following security certificate files to
perform TLS handshake:
•
Root and Intermediate Certificates
•
Local Certificate
•
Private Key
•
Trusted Certificate
When the phones use
TLS
to authenticate with the server, each individual call must setup a
new TLS connection. This can take more time when placing each call. Thus, the IP phones
also have a feature that allows you to setup the connection to the server once and re-use that
one connection for all calls from the phone. It is called
Persistent TLS
. The setup connection
for Persistent TLS is established during the registration of the phone. If the phones are set to
use Persistent TLS, and a call is made from the phone, this call and all subsequent calls use
the same authenticated connection. This significantly reduces the delay time when placing a
call.
On the IP phones, an Administrator can configure TLS and Persistent TLS on a global-basis
only, using the configuration files or the Mitel Web UI.
There is a keep-alive feature for persistent TLS connections only. Administrators can configure
this keep-alive feature using the parameter called “
sip persistent tls keep alive
”. When this
feature is configured, the phone will send keep-alive pings to the proxy server at configured
intervals. The keep-alive feature for persistent TLS connections performs the following
functionalities:
•
After a persistent TLS connection is established or re-established, activate the keep-alive,
which will send CRLF to peer periodically.
•
The phone will retry the connection automatically when a persistent TLS connection is down.
Notes:
1.
There can be only one persistent TLS connection created per phone.
2.
If you configure the phone to use Persistent TLS, you must also specify the Trusted
Certificate file to use. The Root and Intermediate Certificates, Local Certificate, and
Private Key files are optional.
Summary of Contents for 6800 Series
Page 1: ...Mitel 6800 Series SIP Phones 58014473 REV02 RELEASE 4 2 0 SERVICE PACK 2 ADMINISTRATOR GUIDE ...
Page 22: ...Chapter 1 OVERVIEW ...
Page 53: ...Chapter 2 CONFIGURATION INTERFACE METHODS ...
Page 72: ...Chapter 3 ADMINISTRATOR OPTIONS ...
Page 154: ...Chapter 4 CONFIGURING NETWORK AND SESSION INITIATION PROTOCOL SIP FEATURES ...
Page 264: ...Chapter 5 CONFIGURING OPERATIONAL FEATURES ...
Page 590: ...Chapter 6 CONFIGURING ADVANCED OPERATIONAL FEATURES ...
Page 698: ...Chapter 7 ENCRYPTED FILES ON THE IP PHONE ...
Page 704: ...Chapter 8 UPGRADING THE FIRMWARE ...
Page 713: ...Chapter 9 TROUBLESHOOTING ...
Page 743: ...Appendix A CONFIGURATION PARAMETERS ...
Page 1065: ...Appendix B CONFIGURING THE IP PHONE AT THE ASTERISK IP PBX ...
Page 1069: ...Appendix C SAMPLE CONFIGURATION FILES ...
Page 1085: ...Appendix D SAMPLE BLF SOFTKEY SETTINGS ...
Page 1090: ...Appendix E SAMPLE MULTIPLE PROXY SERVER CONFIGURATION ...
Page 1094: ...Appendix F CERTIFICATE SUPPORT ...
Page 1113: ......