Loading A Private Key - AudioCodes MP-11x User Manual

Mediapack series analog voip gateways
Hide thumbs Also See for MP-11x:
Table of Contents

Advertisement

User's Manual
10.2

Loading a Private Key

The device is shipped with a self-generated random private key, which cannot be extracted
from the device. However, some security administrators require that the private key be
generated externally at a secure facility and then loaded to the device through
configuration. Since private keys are sensitive security parameters, take precautions to
load them over a physically-secure connection such as a back-to-back Ethernet cable
connected directly to the managing computer.
To replace the device's private key:
1.
Your security administrator should provide you with a private key in either textual PEM
(PKCS #7) or PFX (PKCS #12) format. The file may be encrypted with a short pass-
phrase, which should be provided by your security administrator.
2.
If the device is operating in HTTPS mode, then set the 'Secured Web Connection
(HTTPS)' field (HTTPSOnly) to HTTP and HTTPS (see 'Configuring Web Security
Settings' on page 73). This ensures that you have a method for accessing the device
in case the new configuration does not work. Restore the previous setting after testing
the configuration.
3.
Open the Certificates page (Configuration tab > System menu > Certificates) and
scroll down to the Upload certificate files from your computer group.
Figure 10-3: Upload Certificate Files from your Computer Group
4.
Fill in the 'Private key pass-phrase' field, if required.
5.
Click the Browse button corresponding to the 'Send Private Key' field, navigate to the
key file, and then click Send File.
6.
If the security administrator has provided you with a device certificate file, load it using
the 'Send Device Certificate' field.
7.
After the files successfully load to the device, save the configuration with a device
reset (see 'Saving Configuration' on page 366); the Web interface uses the new
configuration.
8.
Open the Certificates page again, and verify that under the Certificate information
group (at the top of the page) the 'Private key' read-only field displays "OK"; otherwise,
consult your security administrator.
9.
If the device was originally operating in HTTPS mode and you disabled it in Step 2,
then enable it by setting the 'Secured Web Connection (HTTPS)' field to HTTPS Only.
Version 6.6
113
10. Configuring Certificates
MP-11x & MP-124

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mediapack mp-124

Table of Contents