SIP User's Manual
312
Document #: LTRT-12801
MP-500
MSBG
Parameter
Description
Web/EMS: Peer Host Name
Verification Mode
[PeerHostNameVerificationMo
de]
Determines whether the device verifies the Subject Name of a
remote certificate when establishing TLS connections.
[0]
Disable = Disable (default).
[1]
Server Only = Verify Subject Name only when acting as a
server for the TLS connection.
[2]
Server & Client = Verify Subject Name when acting as a
server or client for the TLS connection.
When a remote certificate is received and this parameter is not
disabled, the SubjectAltName value is compared with the list of
available Proxies. If a match is found for any of the configured
Proxies, the TLS connection is established.
The comparison is performed if the SubjectAltName is either a
DNS name (DNSName) or an IP address. If no match is found
and the SubjectAltName is marked as ‘critical’, the TLS
connection is not established. If DNSName is used, the certificate
can also use wildcards (‘*’) to replace parts of the domain name.
If the SubjectAltName is not marked as ‘critical’ and there is no
match, the CN value of the SubjectName field is compared with
the parameter TLSRemoteSubjectName. If a match is found, the
connection is established. Otherwise, the connection is
terminated.
Web: TLS Client Verify Server
Certificate
EMS: Verify Server Certificate
[VerifyServerCertificate]
Determines whether the device, when acting as client for TLS
connections, verifies the Server certificate. The certificate is
verified with the Root CA information.
[0]
Disable (default).
[1]
Enable.
Note:
If Subject Name verification is necessary, the parameter
PeerHostNameVerificationMode must be used as well.
Web/EMS: TLS Remote Subject
Name
[TLSRemoteSubjectName]
Defines the Subject Name that is compared with the name
defined in the remote side certificate when establishing TLS
connections.
If the SubjectAltName of the received certificate is not equal to
any of the defined Proxies Host names/IP addresses and is not
marked as 'critical', the Common Name (CN) of the Subject field
is compared with this value. If not equal, the TLS connection is
not established. If the CN uses a domain name, the certificate
can also use wildcards (‘*’) to replace parts of the domain name.
The valid range is a string of up to 49 characters.
Note:
This parameter is applicable only if the parameter
PeerHostNameVerificationMode is set to 1 or 2.
Содержание mediapack MP-500
Страница 1: ...Document LTRT 12801 October 2009 User s Manual Version 5 8...
Страница 2: ......
Страница 22: ...SIP User s Manual 22 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 24: ...SIP User s Manual 24 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 290: ...SIP User s Manual 290 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 440: ...SIP User s Manual 440 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 564: ...SIP User s Manual 564 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 566: ...SIP User s Manual 566 Document LTRT 12801 MP 500 MSBG Reader s Notes...
Страница 573: ...Version 5 8 573 October 2009 SIP User s Manual 13 Technical Specifications Reader s Notes...
Страница 574: ...User s Manual Version 5 8 www audiocodes com...