SIP User's Manual
194
Document #: LTRT-65409
MediaPack
Series
3.
In the 'Subject Name' field, enter the DNS name, and then click
Generate CSR
. A
textual certificate signing request, that contains the SSL device identifier, is displayed.
4.
Copy this text and send it to your security provider; the security provider (also known
as Certification Authority or CA) signs this request and send you a server certificate for
the device.
5.
Save the certificate in a file (e.g., cert.txt). Ensure the file is a plain-text file with the
‘BEGIN CERTIFICATE’ header. Below is an example of a Base64-Encoded X.509
Certificate.
-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIEAgAAADANBgkqhkiG9w0BAQQFADA/MQswCQYDVQQGEwJGUj
ETMBEGA1UEChMKQ2VydGlwb3N0ZTEbMBkGA1UEAxMSQ2VydGlwb3N0ZSBTZXJ2ZXVy
MB4XDTk4MDYyNDA4MDAwMFoXDTE4MDYyNDA4MDAwMFowPzELMAkGA1UEBhMCRlIxEz
ARBgNVBAoTCkNlcnRpcG9zdGUxGzAZBgNVBAMTEkNlcnRpcG9zdGUgU2VydmV1cjCC
ASEwDQYJKoZIhvcNAQEBBQADggEOADCCAQkCggEAPqd4MziR4spWldGRx8bQrhZkon
WnNm`+Yhb7+4Q67ecf1janH7GcN/SXsfx7jJpreWULf7v7Cvpr4R7qIJcmdHIntmf7
JPM5n6cDBv17uSW63er7NkVnMFHwK1QaGFLMybFkzaeGrvFm4k3lRefFhJ
gHYezYHf44LvPRPAq3o8pWDguJuZDIULPwvRw==
-----END CERTIFICATE-----
6.
Before continuing, set the parameter HTTPSOnly to 0 to ensure you have a method of
accessing the device in case the new certificate doesn’t work. Restore the previous
setting after testing the configuration.
7.
In the 'Certificates Files' pane, click the
Browse
button corresponding to 'Send Server
Certificate...', navigate to the cert.txt file, and then click
Send File
.
8.
When the operation is completed, save the configuration (refer to 'Saving
Configuration' on page
238
) and restart the gateway; the Embedded Web Server uses
the provided certificate.
Notes:
•
The certificate replacement process can be repeated when necessary
(e.g., the new certificate expires).
•
It is possible to use the IP address of the gateway (e.g., 10.3.3.1) instead
of a qualified DNS name in the Subject Name. This is not recommended
since the IP address is subject to changes and may not uniquely identify
the device.
•
The server certificate can also be loaded via
ini
file using the parameter
HTTPSCertFileName.
5.8.4.2 Client
Certificates
By default, Web servers using SSL provide one-way authentication. The client is certain
that the information provided by the Web server is authentic. When an organizational PKI is
used, two-way authentication may be desired: both client and server should be
authenticated using X.509 certificates. This is achieved by installing a client certificate on
the managing PC, and loading the same certificate (in base64-encoded X.509 format) to
the gateway Trusted Root Certificate Store. The Trusted Root Certificate file should contain
both the certificate of the authorized user and the certificate of the CA.
Since X.509 certificates have an expiration date and time, the gateway must be configured
to use NTP (refer to 'Simple Network Time Protocol Support' on page
371
) to obtain the
current date and time. Without a correct date and time, client certificates cannot work.
Содержание Mediapack mp-11x
Страница 1: ...Document LTRT 65409 August 2007 User s Manual Version 5 2...
Страница 2: ......
Страница 14: ...SIP User s Manual 14 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 18: ...SIP User s Manual 18 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 22: ...SIP User s Manual 22 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 44: ...SIP User s Manual 44 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 47: ...Version 5 2 47 August 2007 SIP User s Manual 4 Getting Started Figure 4 1 Startup Process...
Страница 322: ...SIP User s Manual 322 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 380: ...SIP User s Manual 380 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 388: ...SIP User s Manual 388 Document LTRT 65409 MediaPack Series Reader s Notes...
Страница 390: ...User s Manual Version 5 2 www audiocodes com...