Configuring Security Features
493
This chapter provides information for making configuration changes for the following
security-related features:
Transport Layer Security
Secure Real-Time Transport Protocol
Encrypting Configuration Files
TLS is a commonly-used protocol for providing communications privacy and managing
the security of message transmission, allowing IP phones to communicate with other
remote parties and connect to the HTTPS URL for provisioning in a way that is designed
to prevent eavesdropping and tampering.
TLS protocol is composed of two layers: TLS Record Protocol and TLS Handshake
Protocol. The TLS Record Protocol completes the actual data transmission and ensures
the integrity and privacy of the data. The TLS Handshake Protocol allows the server and
client to authenticate each other and negotiate an encryption algorithm and
cryptographic keys before data is exchanged.
The TLS protocol uses asymmetric encryption for authentication of key exchange,
symmetric encryption for confidentiality, and message authentication codes for
integrity.
Symmetric encryption
:
For symmetric encryption, the encryption key and the
corresponding decryption key can be told by each other. In most cases, the
encryption key is the same as the decryption key.
Asymmetric encryption: For asymmetric encryption, each user has a pair of
cryptographic keys – a public encryption key and a private decryption key. The
information encrypted by the public key can only be decrypted by the
corresponding private key and vice versa. Usually, the receiver keeps its private
key. The public key is known by the sender, so the sender sends the information
encrypted by the known public key, and then the receiver uses the private key to
decrypt it.
IP phones support TLS version 1.0. A cipher suite is a named combination of
authentication, encryption, and message authentication code (MAC) algorithms used
to negotiate the security settings for a network connection using the TLS/SSL network
protocol. IP phones support the following cipher suites:
DHE-RSA-AES256-SHA
DHE-DSS-AES256-SHA
Содержание Yealink SIP-T46G
Страница 1: ...啊 ...
Страница 8: ...Administrator s Guide for SIP T2_Series_T4_Series IP Phones viii ...
Страница 28: ...Administrator s Guide for SIP T2_Series_T4_Series IP Phones 14 ...
Страница 70: ...Administrator s Guide for SIP T2_Series_T4_Series IP Phones 56 ...
Страница 129: ...Configuring Basic Features 115 The following shows a portion of the input method file Russian_ime txt ...
Страница 558: ...Administrator s Guide for SIP T2_Series_T4_Series IP Phones 544 ...
Страница 622: ...Administrator s Guide for SIP T2_Series_T4_Series IP Phones 608 ...