Phone Parameters - Administration
Nur für den internen Gebrauch
A31003-S2000-R102-16-7620 02/2016
168
Provisioning Service, Developer’s Guide
c04.fm
System
4.4.6
Security
4.4.6.1
System (V2)
With software version OpenStage V2R2 onwards, the authentication policy for file transfer (see
Section 4.5, "File Transfer") via HTTPS and for the "Send URL" function (see Section 4.4.5.3,
"Send URL") can be configured. When "None" is selected, no certificate check is performed.
With "Trusted", the certificate is only checked against the signature credentials provided by the
remote server, and the expiry date is checked. When "Full" is selected, the certificate is fully
checked against the credentials provided by the remote server for signature, the fields must
match the requested subject/usage, and the expiry date is checked.
Apart from the provisioning service, this can only be done via the local phone menu: Admin >
Security & policies > Certificates > Authentication policy.
>
With firmware version V3, the parameters listed underneath have been moved to
sub-menus.
WBM Name
Item name
Type
Values
Description
SIP server
certificate valida-
tion
voip-server-
validation
Boolean
true
/
false
Default:
false
If enabled, the phone will
validate the server certifi-
cate sent by the SIP serv-
er in order to establish a
TLS connection.
Backup SIP
server certificate
validation
voip-backup-
server-
validation
Boolean
true
/
false
Default:
false
If enabled, the phone will
validate the backup
server certificate sent by
the SIP server in order to
establish a TLS connec-
tion.
Use secure calls
voip-
payload-
security-
allowed
Boolean
true
/
false
Default:
false
If activated, the encryp-
tion of outgoing calls is
enabled, and the phone is
capable of receiving en-
crypted calls.