administration.fm
A31003-C1000-M101-1-76A9, 03/2016
OpenScape Desk Phone CP200/400/600, Administrator Documentation
77
Administration
Security
3.5
Security
3.5.1
System
OpenScape Desk Phone CP phones support secure (i.e. encrypted) speech transmission via
SRTP. For enabling secure (encrypted) calls, a TLS connection to the OpenScape Voice server
is required.
If Use secure calls is activated, the encryption of outgoing calls is enabled, and the phone is
capable of receiving encrypted calls. When the phone is connected to an OpenScape Voice
system, call security is communicated to the user as follows:
•
An icon in the call view tells the user whether a call is secure (encrypted) or not.
•
If an active call changes from secure to insecure, e. g. after a transfer, a popup window and
an alert tone will notify the user.
If SIP server certificate validation resp. Backup SIP server certificate validation is activated, the
phone will validate the server certificate sent by the OpenScape Voice server in order to estab-
lish a TLS connection. The server certificate is validated against the root certificate from the
trusted certificate authority (CA), which must be stored on the phone first. For delivering the
root certificate, a DLS (OpenScape Deployment Service) server is required.
The
SRTP type
sets the key exchange method for SRTP.
MIKEY (Multimedia Internet KEYing) is a key management protocol that is intended for use with
real-time applications. It can specifically be used to set up encryption keys for multimedia ses-
sions that are secured using SRTP.
Use secure calls activates the encryption of outgoing calls, i.e. the phone iscapable of receiving
encrypted calls.
The SRTP type sets the key exchange method (negotiation method) for secure calls via SRTP.
The following encryption key exchange methods are available:
>
For secure (encrypted) calls, it is required that both endpoints support SRTP. The
secure call indication tells the user that the other endpoint has acknowledged the se-
cure connection.
>
In order to use SRTP, the phone must be configured for NTP (for further information
please see Date and Time). The reason is that the key generation (MIKEY) uses the
system time of the particular device as a basis. Thus, encryption will only work cor-
rectly if all devices have the same UTC time.
>
For secure (encrypted) calls, it is required that both endpoints support SRTP. The
secure call indication tells the user that the other endpoint has acknowledged the
secure connection