CHAPTER1 Overview
C448HD C450HD | Users & Administrator's Manual
Remote Configuration Management
AudioCodesdevicesdonothaveanembeddedWebserver.Configurationandmanagementare
performedusingoneofthefollowingremoteinterfaces:
■ MicrosoftTeamsAdminCenter(forNativeTeamsdevices)overHTTPSprotocols,enabled
afterasuccessfulsign-inauthenticationprocess.
■ AudioCodesDeviceManager(partofAudioCodes'OVOCsuite)overHTTPS.
■ DebugginginterfaceoverSSH.NotethatSSHmustbedisabledbydefaultandenabledonly
perspecificcasefordebuggingpurposesonly.
AudioCodes Device Manager Validation
TheAudioCodesNativeTeamsdevicesvalidatetheAudioCodesDeviceManageridentityusinga
knownRootCA:
■ ThedeviceisshippedwithknownRootCAsinstalled.SeeAudioCodesRootCACertificate
onpage10.
■ Fortheinitialconnection,theAudioCodesDeviceManageraccessesdevicesusingaknown
CA.
■ Onceasuccessfulsecuredconnectionhasbeenestablishedbetweenthedeviceandthe
DeviceManager,theusercanreplacetheRootCAontheDeviceManagerandonthe
phone,andre-establishtheconnectionleveraginganyPrivateRootCA.
Sandboxing
AudioCodesdevicesuseAndroidApplicationSandboxsothateachapplicationcanaccessits
owndataandisisolatedfromotherapplications.Thispreventsamaliciousappfromaccessing
thecodeorthedataofotherapplicationsinthesystem.
Device File System
TheAudioCodes device'sfile systemis encryptedonC450HD- DBWdevices.Customers may
enforceapolicyofdeviceencryptionviaMicrosoft'scloud-basedIntuneservice.
Keystore
WithAudioCodesdevices,thecertificatekeysareencryptedonthedevicefilesystem.
Device Certificate
AudioCodesdevicesareshippedwithauniquecertificatewhichissignedbyAudioCodesRoot
CA.Networkadministratorscaninstallathird-partycertificateonthephoneinthecustomer’s
trusted environment. Network administrators should follow the following guidelines when
replacingtheexistingtrustedCAs:
■ ThedevicecertificateURLwillonlybevalidifnoSCEPserverURLispresent
- 8 -