
Chapter 8: Security configurations
Security overview
SIP-based Avaya J100 Series IP Phones provide several updated security features. When the
phone is in a locked state, the user can only receive calls or make emergency calls. User logs and
data are protected with the user account.
Note:
The user cannot make emergency calls in an Open SIP environment.
The following security features are available:
• Supports X509v3–compliant certificates.
• Supports Identity certificate installation using the following methods:
- Enrollment using Simple Certificate Enrollment Protocol (SCEP): Creates a private key
and Certificate Signing Request (CSR) using the SCEP interface.
- Importing key and certificate: Uses an encrypted PKCS#12 file format to import the private
key and certificate.
• Supports Online Certificate Status Protocol (OCSP) for obtaining the revocation status of an
X.509 Digital certificate.
• Supports Public Key Infrastructure (PKI) for users that use third-party certificates for all
Avaya services including database.
• Supports VLAN separation mode using system parameter.
• Supports synchronization of system clock at configured intervals using system parameter.
• Supports display of SSH fingerprint in the ADMIN menu.
• Displays version of OpenSSH and OpenSSL in the ADMIN menu.
• Maintains the integrity and network protection under Denial of Service (DoS) attack, allowing
the system to survive an attack without spontaneous rebooting and to recover to full mode
automatically after the attack is over.
Important:
The ADMIN menu provides access to certain administrative procedures from the phone. You
must change the default password for the ADMIN menu to restrict users from using the
administrative procedures to change the phone configuration.
April 2020
Installing and Administering Avaya J100 series IP Phones in an Open SIP
environment
258