Security Policy File Updates - Avaya 1230 Administration

1200 series software
Hide thumbs Also See for 1230:
Table of Contents

Advertisement

Certificate-based authentication

Security policy file updates

The security policy file contains a set of rules for certificate-based authentication on the
IP Deskphone. The rules include the following:
• CERT_ADMIN_UI_ENABLE Determines if the Certificate Administration user interface is
enabled on the IP Deskphone. The acceptable values are YES and NO; the default value is
NO.
• SECURITY_LOG_UI_ENABLE Determines if the Security Log user interface is enabled on the
IP Deskphone. The acceptable values are YES and NO; the default value is NO.
• KEY_SIZE The default size used when generating keys on the IP Deskphone. Acts as the
minimum allowed key size that should be enforced when loading certificates from the
IP Deskphone. The acceptable values are:
- KEY_SIZE_1024
- KEY_SIZE_1536
- KEY_SIZE_2048
The default value is KEY_SIZE_1024.
• KEY_ALGORITHM The preferred key generation algorithm. The acceptable value is:
- KEY_ALG_RSA
• DWNLD_CFG_SIGNING defines if configuration files are forced to be signed when a customer
certificate is installed.
- NO - automatically accept the downloaded file without authentication
- YES - file must be signed and fully authenticated
The default is NO.
• CUST_CERT_ACCEPT_VAL_NO_CHECK is added to the existing values
(VAL_NO_MANUAL, VAL_MANUAL_A, VAL_MANUAL_B.
The default value is VAL_MANUAL_A).
• SEC_POLICY_ACCEPT is for Security Policy File acceptance ( VAL_MANUAL_A,
VAL_MANUAL_B.
The default value is VAL_MANUAL_A)
• SIGN_SIP_CONFIG_FILES Overrides the file signing of a file, such as the device configuration
file and the dial plan file. You cannot override the file signing of the Security Policy and
Customer Certificates. The acceptable values are:
- YES—Signing is required.
- NO—No authentication check is performed.
The default value is NO.
• FP_PRESENTED If the resource file is not signed and if there are no customer certificates,
then you are prompted with a Finger Print display with the option to accept or reject
• FP_ENTERED If the resource file is not signed and if there are no customer certificates, then
you must manually enter the Finger Print value and then select Accept.
SIP Software for Avaya 1200 Series IP Deskphones-Administration
272
Comments? infodev@avaya.com
March 2015

Advertisement

Table of Contents
loading

This manual is also suitable for:

1220

Table of Contents