User's Manual
10. Configuring Certificates
Version 6.8
101
Mediant 500 E-SBC
2.
Configure a TLS Context with the following certificates:
•
Import the certificate of the CA that signed the certificate of the SIP client, into the
Trusted Root Store so that the device can authenticate the client (see 'Importing
Certificates and Certificate Chain into Trusted Certificate Store' on page
•
Make sure that the TLS certificate is signed by a CA that the SIP client trusts so
that the client can authenticate the device.
10.1.7.2 TLS for Remote Device Management
By default, servers using TLS provide one-way authentication. The client is certain that the
identity of the server is authentic. When an organizational PKI is used, two-way
authentication may be desired - both client and server should be authenticated using X.509
certificates. This is achieved by installing a client certificate on the management PC and
loading the root CA's certificate to the device's Trusted Root Certificate Store. The Trusted
Root Certificate file may contain more than one CA certificate combined, using a text
editor.
To enable mutual TLS authentication for HTTPS:
1.
Set the 'Secured Web Connection (HTTPS)' field to
HTTPS Only
in the Web Security
Settings page (see Configuring Web Security Settings on page
) to ensure you have
a method for accessing the device in case the client certificate does not work. Restore
the previous setting after testing the configuration.
2.
Open the TLS Contexts page (
Configuration
tab >
System
menu >
TLS Contexts
).
3.
In the TLS Contexts table, select the required TLS Context index row, and then click
the
Context Trusted-Roots
button, located at the bottom of the TLS Contexts
page; the Trusted Certificates page appears.
4.
Click the
Import
button, and then select the certificate file.
5.
When the operation is complete, set the 'Requires Client Certificates for HTTPS
connection' field to
Enable
in the Web Security Settings page.
6.
Save the configuration with a device reset (see Saving Configuration).
When a user connects to the secured Web interface of the device:
If the user has a client certificate from a CA that is listed in the Trusted Root Certificate
file, the connection is accepted and the user is prompted for the system password.
If both the CA certificate and the client certificate appear in the Trusted Root
Certificate file, the user is not prompted for a password (thus, providing a single-sign-
on experience - the authentication is performed using the X.509 digital signature).
If the user does not have a client certificate from a listed CA or does not have a client
certificate, the connection is rejected.
Notes:
•
The process of installing a client certificate on your PC is beyond the scope of this
document. For more information, refer to your operating system documentation,
and/or consult your security administrator.
•
The root certificate can also be loaded via the Automatic Update facility, using the
HTTPSRootFileName
ini
file parameter.
•
You can enable the device to check whether a peer's certificate has been revoked
by an OCSP server, per TLS Context (see 'Configuring TLS Certificate Contexts'
on page
Содержание Mediant 500 E-SBC
Страница 2: ......
Страница 16: ...User s Manual 16 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 22: ...User s Manual 22 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 23: ...Part I Getting Started with Initial Connectivity...
Страница 24: ......
Страница 26: ...User s Manual 26 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 28: ...User s Manual 28 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 33: ...Part II Management Tools...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 64: ...User s Manual 64 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 82: ...User s Manual 82 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 89: ...Part III General System Settings...
Страница 90: ......
Страница 106: ...User s Manual 106 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 107: ...Part IV General VoIP Configuration...
Страница 108: ......
Страница 238: ...User s Manual 238 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 250: ...User s Manual 250 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 280: ...User s Manual 280 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 329: ...Part V Gateway Application...
Страница 330: ......
Страница 332: ...User s Manual 332 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 352: ...User s Manual 352 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 412: ...User s Manual 412 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 441: ...Part VI Session Border Controller Application...
Страница 442: ......
Страница 489: ...User s Manual 28 SBC Configuration Version 6 8 489 Mediant 500 E SBC...
Страница 510: ...User s Manual 510 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 511: ...Part VII Cloud Resilience Package...
Страница 512: ......
Страница 521: ...Part VIII High Availability System...
Страница 522: ......
Страница 536: ...User s Manual 536 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 537: ...Part IX Maintenance...
Страница 538: ......
Страница 544: ...User s Manual 544 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 546: ...User s Manual 546 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 548: ...User s Manual 548 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 582: ...User s Manual 582 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 600: ...User s Manual 600 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 602: ...User s Manual 602 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 603: ...Part X Status Performance Monitoring and Reporting...
Страница 604: ......
Страница 654: ...User s Manual 654 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 655: ...Part XI Diagnostics...
Страница 656: ......
Страница 672: ...User s Manual 672 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 687: ...Part XII Appendix...
Страница 688: ......
Страница 914: ...User s Manual 914 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 919: ...User s Manual 56 Technical Specifications Version 6 8 919 Mediant 500 E SBC This page is intentionally left blank...
Страница 920: ...User s Manual Ver 6 8 www audiocodes com...