
Configuring Security Features
217
IP phone should verify the certificate sent by the server to decide whether it is
trusted based on the trusted certificates list. The IP phone has 30 built-in trusted
certificates. You can upload 10 custom certificates at most. The format of the trusted
certificate files must be *.pem,*.cer,*.crt and *.der and the maximum file size is
5MB. For more information on 30 trusted certificates, refer to
Appendix C: Trusted
Certificates
on page
257
.
Server Certificate: When clients request a TLS connection with the IP phone, the IP
phone sends the server certificate to the clients for authentication. The IP phone
has two types of built-in server certificates: a unique server certificate and a
generic server certificate. You can only upload one server certificate to the IP
phone. The old server certificate will be overridden by the new one. The format of
the server certificate files must be *.pem and *.cer and the maximum file size is
5MB.
-
A unique server certificate: It is unique to an IP phone (based on the MAC
address) and issued by the Yealink Certificate Authority (CA).
-
A generic server certificate: It issued by the Yealink Certificate Authority (CA).
Only if no unique certificate exists, the IP phone may send a generic certificate
for authentication.
The IP phone can authenticate the server certificate based on the trusted certificates list.
The trusted certificates list and the server certificates list contain the default and custom
certificates. You can specify the type of certificates the IP phone accepts: default
certificates, custom certificates or all certificates.
Common Name Validation feature enables the IP phone to mandatorily validate the
common name of the certificate sent by the connecting server.
And Security verification
rules are compliant with RFC 2818.
Note
Procedure
Configuration changes can be performed using the configuration files or locally.
Configuration
File
<y0000000000xx>.cfg
Configure trusted certificates feature.
Parameters:
security.trust_certificates
security.ca_cert
security.cn_validation
Configure server certificates feature.
In TLS feature, we use the terms trusted and server certificate. These are also known as
CA and device certificates.
Resetting the IP phone to factory defaults will delete custom certificates by default. But
this feature is configurable using the configuration files. For more information on the
configuration parameter, refer to
Transport Layer Security
on page
215
.
Summary of Contents for Yealink SIP-T48G
Page 1: ...啊 ...
Page 12: ...Microsoft Lync Edition Administrator s Guide for SIP T2_Series and T4_Series IP Phones xii ...
Page 19: ...Product Overview 7 Admin User configuration mode 802 1X authentication ...
Page 20: ...Microsoft Lync Edition Administrator s Guide for SIP T2_Series and T4_Series IP Phones 8 ...
Page 248: ...Microsoft Lync Edition Administrator s Guide for SIP T2_Series and T4_Series IP Phones 236 ...
Page 266: ...Microsoft Lync Edition Administrator s Guide for SIP T2_Series and T4_Series IP Phones 254 ...