administration.fm
A31003-S2030-M100-11-76A9, 01/2015
OpenStage SIP V3R3 for OpenScape Voice, Administration Manual
85
Administration
Security
3.4.1.3
SDES Configuration
When "SDES" is selected as SRTP negotiation method (see Section 3.4.1.1, “General Config-
uration”), it can be configured further.
The
SDES status
parameter enables or disables SDES, just like
SRTP type
in System > Se-
curity > System (see Section 3.4.1.1, “General Configuration”). When SDES is disabled,
MIKEY will be used.
The
SDP negotiation
parameter specifies whether the use of SRTP will be forced by the
phone. The following choices are available:
•
"RTP + SRTP" - Both non-encrypted (non-secure) and encrypted (secure) media connec-
tions are offered. Non-encrypted connections are preferred over encrypted connections,
i.e. the phone uses the non-encrypted RTP connection if the remote party accepts it and
only switches to SRTP if RTP is not accepted.
•
With "SRTP only", only an encrypted (secure) media connection is allowed; if the remote
party should not support SRTP, no connection will be established.
•
With "SRTP + RTP", the phone will try to establish an SRTP connection, but fall back to
RTP if this should fail. This is the recommended option.
With
SHA1-80 ranking
and
SHA1-32 ranking
, the ranking for each crypto-suite for negotiation
is defined. Additionally, each crypto-suite can be enabled or disabled.
Administration via WBM
System > Security > SDES config
SDES config
Submit
Reset
SHA1-80 ranking
SHA1-32 ranking
SDES status
SRTP + RTP
SDP negotiation
Disabled
X
X