Validating A Certificate Using The Certificate Trust List - Avaya 1230 Administration

1200 series software
Hide thumbs Also See for 1230:
Table of Contents

Advertisement

In addition, the Signing Certificate cannot be a self-signed root certificate and must have a valid
Subject Key Identifier and an Authority Key Identifier (which uniquely identifies the issuing
certificates).

Validating a certificate using the Certificate Trust List

The high level sequence of procedures for validating a certificate using the Certificat Trust List is as
follows:
1. Create the CTL file including start date, expire date and a list of certificates concatenated
together in PEM format so that the entire file can be signed by a trusted entity. A signed CTL
file consists of the following:
• Validity fields
• NOT_VALID_BEFORE: 23/11/2007 11:12:13
• NOT_VALID_AFTER: 25/10/2011: 22:23:24
• Original unsigned file content
• Digital signature
The parts are appended together with the Validity periods first, followed by the certificates,
and then by the digital signature. The signature must be in the form of a PKCS7 detached
signature of the file in PEM format. A detached signature is a signature that does not embed
the content that is signed.
The IP Deskphone does not accept unsigned CTL files. After a CTL file is accepted, the
included certificates are added to the trusted certificate store of the IP Deskphone.
Important:
Do not insert additional characters between the Certificate and the Digital Signature.
Otherwise, the validation fails. Do not change any information from the original file
content that was used to create the signature. Otherwise the signature becomes invalid
and you must create a new signature.
2. The CTL is provisioned to the IP Deskphone in a secure way. Avaya recommends that you
use HTTPS as the secure method to download the CTL file to the IP Deskphone.
3. The IP Deskphone checks the validity periods as follows:
• Not Valid Before—Not used
• Not Valid After—The IP Deskphone checks this when
- The CTL file is downloaded.
- Every 24 hours.
- When a remote certificate is presented to the IP Deskphone.
- The CTL is expired; the CTL is deleted and an event is logged in the security log.
March 2015
Validating a certificate using the Certificate Trust List
SIP Software for Avaya 1200 Series IP Deskphones-Administration
Comments? infodev@avaya.com
257

Advertisement

Table of Contents
loading

This manual is also suitable for:

1220

Table of Contents