2N Access Unit Configuration Manual
a.
b.
c.
d.
•
•
•
•
•
5.5.4 Certificates
Some2NAccess Unitnetwork services use the Transaction Layer Security (TLS) protocol for
communication with other LAN devices to prevent third parties from monitoring and/or
modifying the communication contents. Unilateral or bilateral authentication based on
certificates and private keys is needed for establishing connections via TLS.
The following2NAccess Unitservices use the TLS protocol:
Web server (HTTPS)
E-mail (SMTP)
802.1x (EAP-TLS)
SIPs
Sets of CA certificates can be uploaded to the2N Access Unit, which are used for identity
verification of the device that the intercom is communicating with, and also of User certificates
and private keys for communication encryption
Each certificate-requiring service can be assigned one of the three certificate sets available; refer
to theWeb Server,E-MailandStreamingsubsections. The certificates can be shared by the
services.
2NAccess Unitaccepts the DER (ASN1) and PEM certificate formats.
2NAccess Unitsupports the AES, DES and 3DES encryption.
2NAccess Unitsupports the following algorithms:
RSA up to 2048bit user certificate keys; internally up to 4096bit keys (during
connection – temporary and equivalence certificates)
Elliptic Curves