Certificates And Security Profiles Within A Provisioned System - Polycom HDX 4000 Series Administrator's Manual

Hide thumbs Also See for HDX 4000 Series:
Table of Contents

Advertisement

Polycom, Inc.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
Setting
Global Responder Address
Use Responder Specified
in Certificate
If you use OCSP, you might need to install one or more additional CA certificates on
the HDX system, for validation of the OCSP response messages.

Certificates and Security Profiles within a Provisioned System

When your HDX system is provisioned through the RealPresence Resource
Manager system and you use PKI certificates, consider the following
information. Be sure to enable provisioning after you follow the procedures
applicable to each Security Profile type.
To use the Maximum Security Profile with provisioning:
The RealPresence Resource Manager system must be using
1
Maximum Security Mode.
You must manually assign the Maximum Security Profile to the HDX
2
endpoint during installation using the setup wizard.
You must observe the following procedures before you enable
3
provisioning on the HDX endpoint:
You must install a signed client certificate on the HDX system to
a
enable the provisioning connection to be authenticated by the
RealPresence Resource Manager system.
Description
Specifies the URI of the responder that services
OCSP requests (for example,
http://responder.example.com/ocsp). This
responder is used for all OCSP validation when
Use Responder Specified in Certificate is
disabled, and is sometimes used even when Use
Responder Specified in Certificate is enabled.
Polycom therefore recommends that you always
enter a Global Responder Address regardless of
the value chosen for the Use Responder
Specified in Certificate setting.
In some cases, the certificate itself includes the
responder address. When this field is enabled, the
HDX system attempts to use the address in the
certificate (when present) instead of the Global
Responder Address specified in the previous
field.
Note: The Polycom HDX system supports only the
use of HTTP URLs in the AIA field of a certificate
when Use Responder Specified in Certificate is
enabled.
Security
8–29

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents