400HD IP Phones Series - Teams Compatible
Administrator's Manual 100 Document #: LTRT-09960
3.5.3.2 Loading the Client Certificate to the Phone
The section shows how to load the Client Certificate to the phone.
To load the root CA certificate to the phone:
Refer to the table below. You can also load the file/s to the phone using the
Configuration File.
Table 3-44: Client Certificate Parameters
Parameter Description
security/sip_certificate_uri
Downloads to the phone from this URI a Client
Certificate for SIP TLS (SIP calls with Transport
Layer Security).
security/sip_private_key_uri
Downloads to the phone from this URI a Client
Private Key for SIP TLS (SIP calls with Transport
Layer Security).
security/ieee802_1x_certificate_uri
Downloads to the phone from this URI a Client
Certificate for 802.1X Authentication.
security/ieee802_1x_private_key_uri
Downloads to the phone from this URI a Client
Private Key for 802.1X authentication. The certificate
must be in .pem format.
security/autoupdate_certificate_uri
Downloads to the phone from this URI an external
certificate that is used to secure the connection with
the automatic provisioning server.
security/autoupdate_private_key_uri
Downloads to the phone from this URI a private key
that is used to secure the connection with the
automatic provisioning server.
3.5.3.3 Enabling Server-side Authentication (Mutual Authentication)
You can enable server-side authentication of a connection with the RADIUS / LDAP and
Provisioning server.
Note: OpenSSL 1.0.1m is supported. This open source version supports SHA2
algorithms.
Table 3-45: Server-side Authentication
Parameter Description
security/ieee802_1x/verify_server_certificate
Configures the phone to verify received server
certificates over a secure EAP-TLS connection.
security/provisioning/verify_server_certificate
Configures the phone to verify received server
certificates over a secure HTTPS connection with
a provisioning server.
security/ldap/RootCAoverLDAP
Controls whether or not use LDAP to search for a
certificate. Valid values (bool):
0 [LDAP will not be used to search for a
certificate]