Tls Certificate Verification Of Neighbor Systems - Cisco TelePresence Video Communication Server Administrator's Manual

Hide thumbs Also See for TelePresence Video Communication Server:
Table of Contents

Advertisement

Setting
Microsoft Office
Communications
Server 2007
SIP SDP
130
attribute line limit
length
SIP multipart
On
MIME strip
mode
SIP UPDATE
On
strip mode
Interworking SIP
Info
search strategy
SIP UDP/BFCP
Off
filter mode
SIP Duo Video
On
filter mode
SIP record route
Hostname
address type
SIP Proxy-
<blank>
Require header
strip list

TLS certificate verification of neighbor systems

When a SIP TLS connection is established between a VCS and a neighbor system, the VCS can be
configured to check the X.509 certificate of the neighbor system to verify its identity. You do this by
configuring the zone's TLS verify mode setting.
If TLS verification is enabled, the neighbor system's FQDN or IP address, as specified in the Peer
address field of the zone's configuration, is used to verify against the certificate holder's name
contained within the X.509 certificate presented by that system. (The name has to be contained in
either the Subject Common Name or the Subject Alternative Name attributes of the certificate.) The
certificate itself must also be valid and signed by a trusted certificate authority.
Note that for traversal server zones, the FQDN or IP address of the connecting traversal client is not
configured, so the required certificate holder's name is specified separately.
If the neighbor system is another VCS, or it is a traversal client / traversal server relationship, the two
systems can be configured to authenticate each other's certificates. This is known as mutual
authentication and in this case each VCS acts both as a client and as a server and therefore you must
ensure that each VCS's certificate is valid both as a client and as a server.
See the
Managing security certificates
for instructions on uploading the VCS's server certificate and uploading a list of trusted certificate
authorities.
Cisco VCS Administrator Guide (X6.1)
Cisco Unified
Nortel
Communications
Communication
Manager
Server 1000
130
130
Off
Off
On
On
Options
Options
On
Off
Off
Off
IP
IP
<blank>
"com.
nortelnetworks.
firewall"
section for more information about certificate verification and
Zones and neighbors
Cisco
Non-
Advanced
registering
Media
device
Gateway
130
130
Off
Off
On
Off
Options
Options
Off
Off
Off
Off
IP
IP
<blank>
<blank>
Page 99 of 401

Advertisement

Table of Contents
loading

Table of Contents