Version 7.2
129
Mediant 500 MSBR
User's Manual
13. Configuring SSL/TLS Certificates
You can also do the following with certificates that are in the Trusted Certificates store:
Delete certificates: Select the required certificate, click
Remove
, and then in the
Remove Certificate dialog box, click
Remove
.
Save certificates to a folder on your PC: Select the required certificate, click
Export
,
and then in the Export Certificate dialog box, browse to the folder on your PC where
you want to save the file and click
Export
.
13.8 Configuring Mutual TLS Authentication
This section describes how to configure mutual (two-way) TLS authentication.
13.8.1 TLS for SIP Clients
When Secure SIP (SIPS) is implemented using TLS, it is sometimes required to use two-
way (mutual) authentication between the device and a SIP user agent (client). When the
device acts as the TLS server in a specific connection, the device demands the
authentication of the SIP client’s certificate. Both the device and the client use certificates
from a CA to authenticate each other, sending their X.509 certificates to one another during
the TLS handshake. Once the sender is verified, the receiver sends its' certificate to the
sender for verification. SIP signaling starts when authentication of both sides completes
successfully.
TLS mutual authentication can be configured for calls by enabling mutual authentication on
the SIP Interface associated with the calls. The TLS Context associated with the SIP
Interface or Proxy Set belonging to these calls are used.
Note:
SIP mutual authentication can also be configured globally for all calls, using the
'TLS Mutual Authentication' (SIPSRequireClientCertificate) parameter (see
Configuring TLS for SIP on page 155).
To configure mutual TLS authentication for SIP messaging:
1.
Enable two-way authentication on the specific SIP Interface:
a.
In the SIP Interfaces table (see Configuring SIP Interfaces on page 325),
configure the 'TLS Mutual Authentication' parameter to
Enable
for the specific
SIP Interface.
b.
Reset the device with a save-to-flash for your settings to take effect.
2.
Configure a TLS Context with the following certificates:
•
Import the certificate of the CA that signed the certificate of the SIP client into the
Trusted Certificates table (certificate root store) so that the device can
authenticate the client (see Importing Certificates into Trusted Root Certificate
Store on page 127).
•
Make sure that the TLS certificate is signed by a CA that the SIP client trusts so
that the client can authenticate the device.
13.8.2 TLS for Remote Device Management
By default, servers using TLS provide one-way authentication. The client is certain that the
identity of the server is authentic. When an organizational PKI is used, two-way
authentication may be desired - both client and server should be authenticated using X.509
certificates. This is achieved by installing a client certificate on the management PC and
Содержание Mediant 500 MSBR
Страница 1: ...User s Manual AudioCodes Family of Multi Service Business Routers MSBR Mediant 500 MSBR Version 7 2 ...
Страница 2: ......
Страница 33: ...Part I Getting Started with Initial Connectivity ...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 45: ...Part II Management Tools ...
Страница 46: ......
Страница 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 115: ...Part III General System Settings ...
Страница 116: ......
Страница 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 137: ...Part IV General VoIP Configuration ...
Страница 138: ......
Страница 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Страница 455: ...Part V Gateway Application ...
Страница 456: ......
Страница 458: ...User s Manual 458 Document LTRT 10375 Mediant 500 MSBR IP to Tel Call Figure 24 1 IP to Tel Call Processing Flowchart ...
Страница 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 625: ...Part VI Session Border Controller Application ...
Страница 626: ......
Страница 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 741: ...Part VII Cloud Resilience Package ...
Страница 742: ......
Страница 751: ...Part VIII Data Router Configuration ...
Страница 752: ......
Страница 753: ......
Страница 754: ......
Страница 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 757: ...Part IX Maintenance ...
Страница 758: ......
Страница 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Страница 837: ...Part X Status Performance Monitoring and Reporting ...
Страница 838: ......
Страница 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 927: ...Part XI Diagnostics ...
Страница 928: ......
Страница 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 977: ...Part XII Appendix ...
Страница 978: ......
Страница 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...