Encrypted Files on the IP Phone
7-2
41-001160-01, Rev 00, Release 2.3
IP Phone Administrator Guide
Encrypted Files on the IP Phone
An encryption feature for the IP phone allows Service Providers the capability of
storing encrypted files on their server to protect against unauthorized access and
tampering of sensitive information (i.e., user accounts, login passwords,
registration information). Service Providers also have the capability of locking a
phone to use a specific server-provided configuration only.
Configuration File Encryption Method
Only a System Administrator can encrypt the configurations files for an IP Phone.
System Administrators use a password distribution scheme to manually
pre-configure or automatically configure the phones to use the encrypted
configuration with a unique key.
From a Microsoft Windows command line, the System Administrator uses an
Aastra-supplied encryption tool called "
anacrypt.exe
" to encrypt the
<MAC>.tuz
file.
This tool processes the plain text
<mac>.cfg
and
aastra.cfg
files and creates
triple-DES encrypted versions called
<mac>.tuz
and
aastra.tuz.
Encryption is
performed using a secret password that is chosen by the administrator.
The encryption tool is also used to create an additional encrypted tag file called
security.tuz
, which controls the decryption process on the IP phones. If
security.tuz
is present on the TFTP/FTP/HTTP server, the IP phones download it
and use it locally to decrypt the configuration information from the
aastra.tuz
and
<mac>.tuz
files. Because only the encrypted versions of the configuration files
need to be stored on the server, no plain-text configuration or passwords are sent
across the network, thereby ensuring security of the configuration data.
Note:
Aastra also supplies encryption tools to support Linux platforms
(
anacrypt.linux
) and Solaris platforms (
anacrypt.sunos
) if required.
Содержание 5i Series
Страница 4: ......
Страница 26: ......
Страница 30: ......
Страница 70: ......
Страница 179: ...Administrator Level Options 41 001160 01 Rev 00 Releaes 2 3 3 91 Administrator Options...
Страница 180: ......
Страница 292: ...Configuration Server Protocol 4 112 41 001160 01 Rev 00 Releaes 2 3 IP Phone Administrator Guide...
Страница 644: ...Operational Features 5 352 41 001160 01 Rev 00 Release 2 3 IP Phone Administrator Guide...
Страница 702: ...Encrypted Files on the IP Phone 7 8 41 001160 01 Rev 00 Release 2 3 IP Phone Administrator Guide...
Страница 712: ......
Страница 976: ......
Страница 980: ......
Страница 1014: ...Sample Configuration Files D 34 41 001160 01 Rev 00 Release 2 3 IP Phone Administrator Guide...
Страница 1016: ...Sample Configuration Files D 36 41 001160 01 Rev 00 Release 2 3 IP Phone Administrator Guide...
Страница 1022: ......
Страница 1026: ......
Страница 1030: ......
Страница 1133: ......