Spectralink 84-Series Series Wireless Telephones Administration Guide
1725-86984-000_P.docx
September 2016
196
CA certificate used for Secure Provisioning
A CA Certificate can be used for Secure Provisioning: FTPS and HTTPS. This prevents the
configuration parameters of a device from being exposed during wireless transfer.
CA certificate used for SIP Communication
Some PBXes allow for communication between the handset and the device to occur using TLS.
A CA certificate can be used to set up MTLS (mutual TLS) between the handset and the PBX in
this case.
Other
CA Certificate used for Browser Communication
CA certificate used for LDAP Communication
Device certificate used for 802.1x Authentication
A device certificate validates the handset to the RADIUS server during EAP-TLS Authentication.
Spectralink 84-Series handsets are shipped with a Spectralink device certificate and its
associated private key known only to the phone which can be used by EAP-TLS for Wi-Fi
security. The Spectra
link device certificate uses the handset’s MAC address as its common
name which is also its Identity.
PAC file
The Protected Access Credential (PAC) is a proprietary Cisco method for provisioning
certificates. The PAC can be either a specific to a device or common to a group of devices. It is
generated by the RADIUS server and must be loaded either manually or automatically. EAP-
FAST is used with Cisco® products and by a number of other WLAN vendors.
Configuring certificates
To configure a certificate, you will follow these general steps:
1
Loading the certificate
2
Assigning the certificate to a Platform or Application profile
3
Connecting the platform to how it will be used
4
Configuring additional parameters (if necessary)
For purposes of configuration, certificates are divided into two different categories
—Platform
and Application. If set, the t
wo platform certificates are stored in the device’s flash memory and
are used by both the Updater and the application parts of the software. If any are set, the six
applic
ation certificates are stored in the device’s RAM and are used by the application part of
the software.