User's Manual
114
Document #: LTRT-65432
MP-11x & MP-124
10.3 Mutual TLS Authentication
By default, servers using TLS provide one-way authentication. The client is certain that the
identity of the server is authentic. When an organizational PKI is used, two-way
authentication may be desired - both client and server should be authenticated using X.509
certificates. This is achieved by installing a client certificate on the managing PC and
loading the root CA's certificate to the device's Trusted Root Certificate Store. The Trusted
Root Certificate file may contain more than one CA certificate combined, using a text
editor.
Since X.509 certificates have an expiration date and time, the device must be configured to
use NTP (see 'Simple Network Time Protocol Support' on page
) to obtain the current
date and time. Without the correct date and time, client certificates cannot work.
To enable mutual TLS authentication for HTTPS:
1.
Set the 'Secured Web Connection (HTTPS)' field to
HTTPS Only
(see 'Configuring
Web Security Settings' on page
) to ensure you have a method for accessing the
device in case the client certificate does not work. Restore the previous setting after
testing the configuration.
2.
Open the Certificates page (see 'Replacing the Device's Certificate' on page
3.
In the
Upload certificate files from your computer
group, click the
Browse
button
corresponding to the 'Send Trusted Root Certificate Store ...' field, navigate to the file,
and then click
Send File
.
4.
When the operation is complete, set the 'Requires Client Certificates for HTTPS
connection' field to
Enable
(see 'Configuring Web Security Settings' on page
5.
Save the configuration with a device reset (see 'Saving Configuration' on page
When a user connects to the secured Web interface of the device:
If the user has a client certificate from a CA that is listed in the Trusted Root Certificate
file, the connection is accepted and the user is prompted for the system password.
If both the CA certificate and the client certificate appear in the Trusted Root
Certificate file, the user is not prompted for a password (thus, providing a single-sign-
on experience - the authentication is performed using the X.509 digital signature).
If the user does not have a client certificate from a listed CA or does not have a client
certificate, the connection is rejected.
Notes:
•
The process of installing a client certificate on your PC is beyond the scope of this
document. For more information, refer to your operating system documentation,
and/or consult your security administrator.
•
The root certificate can also be loaded via the Automatic Update facility, using the
HTTPSRootFileName
ini
file parameter.
•
You can enable the device to check whether a peer's certificate has been revoked
by an Online Certificate Status Protocol (OCSP) server (see Configuring
Certificate Revocation Checking (OCSP) on page
Содержание Media Pack MP-11x
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 25: ...Part I Getting Started with Initial Connectivity...
Страница 26: ......
Страница 35: ...Part II Management Tools...
Страница 36: ......
Страница 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 109: ...Part III General System Settings...
Страница 110: ......
Страница 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 121: ...Part IV General VoIP Configuration...
Страница 122: ......
Страница 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 231: ...Part V Gateway Application...
Страница 232: ......
Страница 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 327: ...Part VI Stand Alone Survivability Application...
Страница 328: ......
Страница 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 361: ...Part VII Maintenance...
Страница 362: ......
Страница 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 409: ...Part VIII Status Performance Monitoring and Reporting...
Страница 410: ......
Страница 441: ...Part IX Diagnostics...
Страница 442: ......
Страница 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 471: ...Part X Appendix...
Страница 472: ......
Страница 650: ...International Headquarters Contact us www audiocodes com info Website www audiocodes com Document LTRT 65432...