Secure Srst Authentication And Encryption - Cisco CP-7911G-CH1 System Administrator Manual

Unified sccp and sip srst
Table of Contents

Advertisement

Information About Configuring Secure SRST

Secure SRST Authentication and Encryption

Figure 2
process.
Figure 2
7940/7960
Table 3
Process Steps Description or Detail
1.
2.
3.
4.
Cisco Unified SCCP and SIP SRST System Administrator Guide
184
illustrates the process of secure SRST authentication and encryption, and
Secure Cisco Unified SRST Authentication and Encryption
CAPF
TFTP
4
2
4
LSC
SEPMACxxxx.cnf.xml
7970
MIC
6
IP
6b
IP phone
LSC/MIC
Overview of the Process of Secure SRST Authentication and Encryption
The CA server, whether it is a Cisco IOS router CA or a third-party CA, issues a
device certificate to the SRST gateway, enabling credentials service. Optionally, the
certificate can be self-generated by the SRST router using a Cisco IOS CA server.
The CA router is the ultimate trustpoint for the Certificate Authority Proxy Function
(CAPF). For more information on CAPF, see
Security
Guide.
The CAPF is a process where supported devices can request a locally significant
certificate (LSC). The CAPF utility generates a key pair and certificate that is specific
for CAPF, copies this certificate to all Cisco Unified Communications Manager
servers in the cluster, and provides the LSC to the Cisco Unified IP Phone.
An LSC is required for Cisco Unified IP Phones that do not have a manufacturing
installed certificate (MIC). The Cisco 7970 is equipped with a MIC and therefore does
not need to go through the CAPF process.
Cisco Unified Communications Manager requests the SRST certificate from
credentials server, and the credentials server responds with the certificate.
For each device, Cisco Unified CM uses the TFTP process and inserts the certificate
into the SEPMACxxxx.cnf.xml configuration file of the Cisco Unified IP Phone.
Cisco Unified
Communications Manager
Cisco Unified
SRST cert
5
3
TLS handshake
6a
Cisco Unified
SRST cert
Configuring Secure SRST for SCCP and SIP
Table 3
Cisco IOS router CA
or third-party CA
1
Cisco Unified
SRST cert
Credentials
service
V
Cisco Unified
SRST
Cisco Communications Manager
describes the
OL-13143-04

Advertisement

Table of Contents
loading

Table of Contents