Enabling Encryption For Videoconferences - Avaya XT Series Deployment Manual

Hide thumbs Also See for XT Series:
Table of Contents

Advertisement

Securing your XT Series
Field
Verify Certificate Key Usage
Verify Certificate Revocation
3. Select Save.
4. (Optional) If required by your organization's security policies, continue with
Encryption for Videoconferences

Enabling Encryption for Videoconferences

You can add security to videoconferences (SIP and H.323 calls) using encryption. The call detail
records and the Statistics page display information regarding the encryption status of the
videoconference.
About this task
The system can secure videoconference sessions via encrypted connections, in both point-to-
point calls and videoconferences, as follows:
• For SIP connections, you can encrypt the actual media of SIP connections via SRTP.
Secure Real-time Transport Protocol (SRTP) adds security to the standard RTP protocol,
which is used to send media (video and audio) between devices in SIP calls. It offers security
with encryption, authentication and message integrity. The encryption uses a symmetric key
generated at the start of the call, and being symmetric, the same key locks and unlocks the
data. So to secure transmission of the symmetric key, it is sent safely during call setup using
TLS.
• For H.323 connections, encryption is enabled via H.235.
August 2020
Description
Select Yes to ensure that the XT Series only
accepts certificates if a 'Key Usage' or
'Extended Key Usage' value is validated.
Select No to accept certificates without
performing a 'Key Usage' or 'Extended Key
Usage' check.
Select Yes always to ensure that the XT Series
checks if the certificate has been revoked. It
treats indeterminate results as failures.
Select Yes if possible to check if the certificate
has been revoked and to reject certificates
which have been known to be revoked but to
allow certificates if the result of the check is
indeterminate due to missing revocation
information in the certificate or a failure to check
the revocation status, such as in situations
where there is no response from the OCSP
responder, or an inability to download the CRL,
and so on.
Select No to disable certificate checking.
on page 250.
Deployment Guide for Avaya XT Series
Comments on this document? infodev@avaya.com
Enabling
250

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents