E-DOC-CTC-20071119-0003 v1.0
16
2|
Configuring CWMP on the Thomson Gateway
2.1.2
TLS Certificates
TLS certificate validation
The Thomson Gateway supports two types of TLS/SSL authentication via certificate validation:
Client authentication
: if the Thomson Gateway (TLS client) is requested by the ACS (TLS server) to send
its certificate, the Thomson Gateway must reply with its own certificate. Client authentication may be
useful if the ACS needs to send sensitive data to the Thomson Gateway.
Server authentication
: the Thomson Gateway (TLS client) is responsible for checking the ACS (TLS
server) identity. Requesting the ACS to authenticate makes sure the Thomson Gateway connects to a
trusted ACS. This avoids malicious people to connect to the Thomson Gateway and reconfigure the
whole device.
Server authentication requires
ACS certificate validation
: the Thomson Gateway receives a server
certificate and validates this with a pre-provisioned CA (Certificate Authority) certificate.
TLS authentication via certificate validation is
not
supported for TLS/SSL between the Thomson Gateway and
the file server.
Listing Thomson Gateway certificate information
Only one certificate is used for
client authentication
.
This certificate can only be altered through file upload (using FTP or TR-069). If no certificate is found when
the Thomson Gateway is booting, it generates its own certificate and private/public key pair. The Thomson
Gateway signs the certificate using its own private key.
To display the certificate of the Thomson Gateway, execute following command:
=>:tls self cert list expand=enabled
1-
Subject
: /CN=SpeedTouch 780/O=THOMSON/OU=0639JT008
Not Before
: Jan
1 00:00:00 2005 GMT
Not After
: Dec 31 00:00:00 2024 GMT
Issuer
: /CN=SpeedTouch 780/O=THOMSON/OU=0639JT008
Key Strength
: 1024 bit
Certificate
: /dl/tls/cert0001.pem
-----BEGIN CERTIFICATE-----
MIIB9TCCAV6gAwIBAgIEirL3QTANBgkqhkiG9w0BAQUFADA/MRcwFQYDVQQDEw5T
cGVlZFRvdWNoIDc4MDEQMA4GA1UEChMHVEhPTVNPTjESMBAGA1UECxMJMDYzOUpU
MDA4MB4XDTA1MDEwMTAwMDAwMFoXDTI0MTIzMTAwMDAwMFowPzEXMBUGA1UEAxMO
U3BlZWRUb3VjaCA3ODAxEDAOBgNVBAoTB1RIT01TT04xEjAQBgNVBAsTCTA2MzlK
VDAwODCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAzzFG44ShTLd8mq8iGrsG
adtKkVJlgaL0D+hanq6or0xVb51Vjn3spuVcNZg9B8xAjP1V
v5gQcNFv3lmeB7x0Gcfcf5eq7OLh3a9nVO0BPx3wcSBZ3hcxJtRaPzCU
r6kW3aVe/3JRle9MuzhKZTsCAwEAATANBgkqhkiG9w0BAQUFAAOBgQCU7J7L7n/c
Pony41ik6c7kXubwSsg0MRFxLVtkIlcVAc0rcY3CWA0QdbkLeOTE8b54
3f94bsydlIUmh/8xBgcRxOSH9Ws06Dhp3RMwgmTzotl0KSwSAIJRM9gV/uPlrZgx
CLYxODvcT5KyJlKIISVPhWVjYU3yTo0lLw==
-----END CERTIFICATE-----
Содержание TR-069
Страница 2: ......
Страница 3: ...Thomson Gateway TR 069 Configuration Guide R7 4 and higher ...
Страница 18: ...E DOC CTC 20071119 0003 v1 0 12 1 Introduction ...
Страница 36: ...E DOC CTC 20071119 0003 v1 0 30 2 Configuring CWMP on the Thomson Gateway ...
Страница 74: ...E DOC CTC 20071119 0003 v1 0 68 5 WAN Connections ...
Страница 106: ...E DOC CTC 20071119 0003 v1 0 100 6 Service Provisioning ...
Страница 109: ......