Version 6.6
325
October 2014
Installation & Operation Manual
33. Configuring Security Settings
33.10
X.509 Public Key Infrastructure
X.509 is an ITU-T standard for Public Key Infrastructure (PKI). The X.509 standard
was adapted to the Internet by the IETF PKIX working group (RFC 3280) and is
currently the most widely used PKI standard that is utilized by many security
applications, including SIP/TLS, HTTPS (SSL) and IPSEC/IKE.
The X.509 standard is typically used by applications that perform Public Key
cryptography, also known as Asymmetric cryptography. The latter is a form of
cryptography in which a user has a pair of cryptographic keys – a Public Key and a
Private Key. The Private Key is kept secret, while the Public Key may be widely
distributed. These keys are related mathematically; however, the Private Key can not
be practically derived from the Public Key. A message encrypted with the Public Key
can be decrypted only with the Private Key.
X.509 Public Key infrastructure uses Certificates to bind together a Public Key with an
identity information, such as the name of the person or organization and their address.
The Certificates are distributed between the participating parties and can be used to
verify that the Public Key belongs to an individual.
In a typical PKI scheme, Certificates are issued by a Certificate Authority (CA) and
provide an attestation by the certificate signer (CA) that the identity information and
the public key belong together. CAs are organized in a structured hierarchical system
that represents the trust relationships between them.
Each party has a list of Trusted Root Certificates – certificates of the CAs (or their
roots) that are well-known and trusted by the party. When the certificate from the other
party is received, its signing entity (CA) is compared with the Trusted Root Certificates
list and if the match is found, the certificate is accepted.
In the Mediant 8000 Media Gateway, X.509 Certificates are used by the following
applications:
SIP/TLS – for secure SIP call control messaging.
HTTPS (SSL) – for internal communication between the SC and the Media
Gateway boards (e.g. for online provisioning of Auxiliary Files) and for secure
access to the Media Gateway board's advanced status summary via WEB
interface.
IPSEC/IKE – for secure MGCP/MEGACO call control messaging; X.509
Certificates may be used as an alternative to pre-shared key authentication
mode.
The Mediant 8000 Media Gateway uses the following files to implement X.509 Public
Key Infrastructure:
Private Key File
– contains a private key that is used to perform decryption; it is
the most sensitive part of security data and should never be disclosed to other
entities.
Certificate File
– contains a digital signature that binds together Public Key with
an identity information; Certificate may be issued by a CA (e.g. Veritas) or be self-
signed (issued by the entity itself).
CA Certificate File
– certificate of the CA that issued Certificate for the Mediant
8000 Media Gateway; optional file that if present is used to validate the Certificate
file.
Содержание Mediant 8000
Страница 1: ...Media Gateway Mediant 8000 Installation Operation Maintenance Manual Version 6 6 Document LTRT 92224...
Страница 2: ......
Страница 28: ...Installation Operation Manual 28 Document LTRT 92224 Mediant 8000 This page is left blank intentionally...
Страница 32: ...Installation Operation Manual 32 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 33: ...Part I Hardware Overview This part describes the hardware overview of the Mediant 8000 chassis...
Страница 34: ......
Страница 36: ...Installation Operation Manual 36 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 38: ...Installation Operation Manual 38 Document LTRT 92224 Mediant 8000 Figure 3 2 Mediant 8000 Back View...
Страница 44: ...Installation Operation Manual 44 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 46: ...Installation Operation Manual 46 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 52: ...Installation Operation Manual 52 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 56: ...Installation Operation Manual 56 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 62: ...Installation Operation Manual 62 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 88: ...Installation Operation Manual 88 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 90: ......
Страница 108: ...Installation Operation Manual 108 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 126: ...Installation Operation Manual 126 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 156: ...Installation Operation Manual 156 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 158: ......
Страница 176: ...Installation Operation Manual 176 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 264: ......
Страница 276: ...Installation Operation Manual 276 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 292: ...Installation Operation Manual 292 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 302: ...Installation Operation Manual 302 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 400: ...Installation Operation Manual 400 Document LTRT 92224 Mediant 8000 This page is left intentionally blank...
Страница 416: ...Installation Operation Manual 416 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 458: ...Installation Operation Manual 458 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 526: ...Installation Operation Manual 526 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 544: ...Installation Operation Manual 544 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 546: ......
Страница 724: ...Installation Operation Manual 724 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 775: ...Part VI Maintenance This part describes the Mediant 8000 maintenance procedures...
Страница 776: ......
Страница 790: ...Installation Operation Manual 790 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 810: ...Installation Operation Manual 810 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 832: ...Installation Operation Manual 832 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 834: ......
Страница 844: ...Installation Operation Manual 844 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 856: ...Installation Operation Manual 856 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 870: ...Installation Operation Manual 870 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 876: ...Installation Operation Manual 876 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 878: ...Installation Operation Manual 878 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 879: ...Part VIII Appendices This part describes additional Mediant 8000 configuration procedures...
Страница 880: ......
Страница 890: ...Installation Operation Manual 890 Document LTRT 92224 Mediant 8000 Figure B 1 HSRP VRRP Configuration...
Страница 904: ...Installation Operation Manual 904 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 910: ...Installation Operation Manual 910 Document LTRT 92224 Mediant 8000 This page is intentionally left blank...
Страница 924: ...Media Gateway Mediant 8000 www audiocodes com Installation Operation Maintenance Manual...