Loading A Private Key - AudioCodes MediaPack Series MP-11x User Manual

Analog voip media gateways mediapack series
Hide thumbs Also See for MediaPack Series MP-11x:
Table of Contents

Advertisement

User's Manual
group (at the top of the page), the 'Private key' read-only field displays "OK";
otherwise, consult your security administrator:
Figure 9-2: Private key "OK" in Certificate Information Group
10.
If the device was originally operating in HTTPS mode and you disabled it in Step 2,
then return it to HTTPS by setting the 'Secured Web Connection (HTTPS)' parameter
to HTTPS Only, and then reset the device with a flash burn.
Notes:
9.2

Loading a Private Key

The device is shipped with a self-generated random private key, which cannot be extracted
from the device. However, some security administrators require that the private key be
generated externally at a secure facility and then loaded to the device through
configuration. Since private keys are sensitive security parameters, take precautions to
load them over a physically-secure connection such as a back-to-back Ethernet cable
connected directly to the managing computer.
To replace the device's private key:
1.
Your security administrator should provide you with a private key in either textual PEM
(PKCS #7) or PFX (PKCS #12) format. The file may be encrypted with a short pass-
phrase, which should be provided by your security administrator.
2.
If the device is operating in HTTPS mode, then set the 'Secured Web Connection
(HTTPS)' field (HTTPSOnly) to HTTP and HTTPS (see 'Configuring Web Security
Settings' on page 67). This ensures that you have a method for accessing the device
in case the new configuration does not work. Restore the previous setting after testing
the configuration.
Version 6.6
The certificate replacement process can be repeated when necessary
(e.g., the new certificate expires).
It is possible to use the IP address of the device (e.g., 10.3.3.1) instead
of a qualified DNS name in the Subject Name. This is not recommended
since the IP address is subject to change and may not uniquely identify
the device.
The device certificate can also be loaded via the Automatic Update
Facility by using the HTTPSCertFileName ini file parameter.
95
9. Configuring Certificates
MP-11x & MP-124

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents