Configuring Security Features
233
The system can encrypt SIP with TLS, which is called SIPS. When TLS is enabled for the SIP
account, the message of the SIP account will be encrypted after the successful TLS negotiation.
Certificates
The system can serve as a TLS client or a TLS server. The TLS requires the following security
certificates to perform the TLS handshake:
Trusted Certificate
: When the system requests a TLS connection with a server, the system
should verify the certificate sent by the server to decide whether it is trusted based on the
trusted certificates list. The system has 36 built-in trusted certificates. You can upload up to
10 custom certificates to the system. The format of the certificates must be *.pem, *.cer,
*.crt and *.der. For more information on 36 trusted certificates, refer to
on page
Server Certificate
: When clients request a TLS connection with the system, the system
sends the server certificate to the clients for authentication. The system has two types of
built-in server certificates: a unique server certificate and a generic server certificate. You
can only upload one server certificate to the system. The old server certificate will be
overridden by the new one. The format of the server certificate files must be *.pem and
*.cer.
-
A unique server certificate
: It is installed by default and is unique to a system
(based on the MAC address) and issued by the Yealink Certificate Authority (CA).
-
A generic server certificate
: It is installed by default and is issued by the Yealink
Certificate Authority (CA). Only if no unique certificate exists, the system may send a
generic certificate for authentication.
The system can authenticate the server certificate based on the trusted certificates list. The
trusted certificates list and the server certificates list contain the default and custom certificates.
You can specify the type of certificates the system accepts: default certificates, custom
certificates, or all certificates.
Common Name Validation feature enables the system to mandatorily validate the common
name of the certificate sent by the connecting server.
And Security verification rules are
compliant with RFC 2818.
TLS parameters on the system are described below:
Parameter
Description
Configuration Method
Transport
Configures the type of transport protocol.
You can configure it for the
Zoom/Pexip/BlueJeans/Mind/Custom
platform, or SIP account separately.
UDP
—provides best-effort transport via
UDP for the SIP signaling.
TCP
—provides reliable transport via TCP
for SIP signaling.
Remote Control
Web User Interface
Содержание MeetingSpace VC800
Страница 1: ......
Страница 4: ......
Страница 14: ...Administrator s Guide for Yealink VC800 Video Conferencing System xiv...
Страница 26: ...Administrator s Guide for Yealink VC800 Video Conferencing System 12...
Страница 36: ...Administrator s Guide for Yealink VC800 Video Conferencing System 22...
Страница 88: ...Administrator s Guide for Yealink VC800 Video Conferencing System 74...
Страница 240: ...Administrator s Guide for Yealink VC800 Video Conferencing System 226...
Страница 262: ...Administrator s Guide for Yealink VC800 Video Conferencing System 248...
Страница 268: ...Administrator s Guide for Yealink VC800 Video Conferencing System 254...
Страница 286: ...Administrator s Guide for Yealink VC800 Video Conferencing System 272...
Страница 292: ...Administrator s Guide for Yealink VC800 Video Conferencing System 278...