Configuring Secure SRST for SCCP and SIP
Information About Configuring Secure SRST
180
Cisco Unified SCCP and SIP SRST System Administrator Guide
OL-13143-04
in clear-text mode is built into Cisco Unified IP phone firmware. See
Media and Signaling
Authentication and Encryption Feature for Cisco IOS MGCP Gateways
for more information on
clear-text mode.
Signaling Security on Unify SRST - TLS
•
SRST Routers and the TLS Protocol, page 180
•
Certificates Operation on Secure SRST, page 180
•
Certificates Transport from CUCM to Secure SRST, page 182
SRST Routers and the TLS Protocol
Transport Layer Security (TLS) Version 1.0 provides secure TCP channels between Cisco Unified IP
phones, secure Cisco Unified SRST Routers, and Cisco Unified Communications Manager. The TLS
process begins with the Cisco Unified IP Phone establishing a TLS connection when registering with
Cisco Unified Communications Manager. Assuming that Cisco Unified Communications Manager is
configured to fallback to Cisco Unified SRST, the TLS connection between the Cisco Unified IP Phones
and the secure Cisco Unified SRST Router is also established. If the WAN link or Cisco
Unified Communications Manager fails, call control reverts to the Cisco Unified SRST router.
Certificates Operation on Secure SRST
•
Cisco Unified SRST Routers and PKI, page 180
•
Cisco IOS Credentials Server on Secure SRST Routers, page 181
•
Generating a Certificate for the Credentials Server, page 181
Cisco Unified SRST Routers and PKI
The transfer of certificates between a Cisco Unified SRST router and Cisco Unified Communications
Manager is mandatory for secure SRST functionality. Public key infrastructure (PKI) commands are
used to generate, import, and export the certificates for secure Cisco Unified SRST.
Table 1
shows the
secure SRST-supported Cisco Unified IP Phones and the appropriate certificate for each phone. The
“Additional References” section on page 230
contains information and configurations about generating,
importing, and exporting certificates that use PKI commands.
Note
Certificate text can vary depending on your configuration. You may also need CAP-RTP-00X or
CAP-SJC-00X for older phones that support manufacturing installed certificate (MIC).
Note
Cisco supports Cisco IP Phones 7900 series phone memory reclamation phones that use MIC or locally
significant certificate (LSC) certificates.