Huawei IP Phone eSpace
7810&7820&7830&7850&7870&7803X
Administrator Guide
2 Single IP Phone Configuration
Issue 01 (2011-12-31)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
84
Figure 2-43
TLS/SSL data transmission process
1.
The client sends a ClientHello request to the server, asking to set up a connection. The
request contains the encryption methods supported by the client for negotiation.
2.
The server sends a ServerHello message back to negotiate an encryption method and
sends a trusted certificate to the client. The certificate contains the public key of the
server.
3.
If the client trusts the server, the client sends the server the session key that is encrypted
by the public key of the server. The client also asks the server to use the session key for
file encryption and transmission.
4.
The server receives the information from the client and uses the session key to encrypt
all of the information that will be sent to the client.
An IP phone functions as a client
When an IP phone initiates an SSL connection, the IP phone functions as a client. Generally,
the client uses the authentication certificate to determine whether the server is reliable, for
example, when an IP phone is automatically upgraded in HTTPS mode. To configure the auto
provision function, click the
Security
tab, and click
Trusted Certificates
, as shown in
Figure
2-44
.