Trusted Certificates - Avaya J100 Series Installing And Administering

Third-party call control setup
Hide thumbs Also See for J100 Series:
Table of Contents

Advertisement

Security configurations
• Basic Contraints
• Subject Alternative Name
• Key Usage Extensions
• Extended Key Usage
To validate the identity of a received certificate, the following process is followed:
• Verification of certificate chain up to the trusted entity.
• Verification of the signature.
• Verification of the revocation status through OCSP.
• Verification of the certification validity (not-before and not-after dates are checked).
• Verification of the certificate usage restrictions.
• Verification of the identity against the certificate.
Subject Alternative Field (SAN)
While validating the certificates, the phone verifies whether the presented certificate has a SAN
field or not. The SAN field simplifies the server configuration. With the SAN field, you can specify
additional host names, such as IP addresses or common names, to use a single SSL Certificate.
• If the certificate does not have the SAN field, the phone validates the Common Name (CN)
fields of the certificate. In this case, you need the following CN fields:
- SIP domain name
- IP address
• If the certificate has the SAN field, the following attributes for an HTTP-TLS connection are
present:
- Provisioning phone with only an IP address
• In the SAN field, IP attribute with IP of HTTPS server is present.
- Provisioning phone with FQDN of HTTPS server
• In the SAN field, IP attribute with the IP address of HTTPS server is present.
• DNS attribute with FQDN of HTTPS server.
Note:
While provisioning the phone with the FQDN of HTTPS server, you need two attributes in the
SAN field:
• DNS attribute with FQDN
• IP attribute IP address

Trusted certificates

Trusted certificates are the root certificates that are used to verify the received certificates. These
certificates are installed on the phone through the http server using settings file and are used to
validate server certificates during a TLS session.
August 2018
Installing and Administering Avaya J100 series IP Phones in third-party call control
setup
Comments on this document? infodev@avaya.com
90

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

J139J129J169J179Jbm24

Table of Contents