Mutual Tls Authentication - AudioCodes MediaPack Series MP-11x User Manual

Analog voip media gateways mediapack series
Hide thumbs Also See for MediaPack Series MP-11x:
Table of Contents

Advertisement

3.
Open the Certificates page (Configuration tab > System menu > Certificates) and
scroll down to the Upload certificate files from your computer group.
Figure 9-3: Upload Certificate Files from your Computer Group
4.
Fill in the 'Private key pass-phrase' field, if required.
5.
Click the Browse button corresponding to the 'Send Private Key' field, navigate to the
key file, and then click Send File.
6.
If the security administrator has provided you with a device certificate file, load it using
the 'Send Device Certificate' field.
7.
After the files successfully load to the device, save the configuration with a device
reset (see 'Saving Configuration' on page 324); the Web interface uses the new
configuration.
8.
Open the Certificates page again, and verify that under the Certificate information
group (at the top of the page) the 'Private key' read-only field displays "OK"; otherwise,
consult your security administrator.
9.
If the device was originally operating in HTTPS mode and you disabled it in Step 2,
then enable it by setting the 'Secured Web Connection (HTTPS)' field to HTTPS Only.
9.3

Mutual TLS Authentication

By default, servers using TLS provide one-way authentication. The client is certain that the
identity of the server is authentic. When an organizational PKI is used, two-way
authentication may be desired - both client and server should be authenticated using X.509
certificates. This is achieved by installing a client certificate on the managing PC and
loading the root CA's certificate to the device's Trusted Root Certificate Store. The Trusted
Root Certificate file may contain more than one CA certificate combined, using a text
editor.
Since X.509 certificates have an expiration date and time, the device must be configured to
use NTP (see 'Simple Network Time Protocol Support' on page 99) to obtain the current
date and time. Without the correct date and time, client certificates cannot work.
User's Manual
96
MP-11x & MP-124
Document #: LTRT-65417

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents