CHAPTER1 Overview
C448HD C450HD | Users & Administrator's Manual
Remote Configuration Management
AudioCodesdevicesdonothaveanembeddedWebserver.Configurationandmanagementare
performedusingoneofthefollowingremoteinterfaces:
■ MicrosoftTeamsAdminCenter(forNativeTeamsdevices)overHTTPSprotocols,enabled
afterasuccessfulsign-inauthenticationprocess.
■ AudioCodesDeviceManager(partofAudioCodes'OVOCsuite)overHTTPS.
■ DebugginginterfaceoverSSH.NotethatSSHmustbedisabledbydefaultandenabledonly
perspecificcasefordebuggingpurposesonly.
AudioCodes Device Manager Validation
TheAudioCodesNativeTeamsdevicesvalidatetheAudioCodesDeviceManageridentityusinga
knowntrustedcertificate:
■ Thedeviceisshippedwithknowntrustedcertificateinstalled.SeeAudioCodesRootCA
Certificateonpage10.
■ Fortheinitialconnection,theAudioCodesDeviceManageraccessesdevicesusingaknown
trustedcertificate.
■ Onceasuccessfulsecuredconnectionhasbeenestablishedbetweenthedeviceandthe
DeviceManager,theusercanreplacethetrustedcertificateontheDeviceManagerandon
thephone,andre-establishtheconnectionleveraginganyPrivateTrustedCertificate.
Sandboxing
AudioCodesdevicesuseAndroidApplicationSandboxsothateachapplicationcanaccessits
owndataandisisolatedfromotherapplications.Thispreventsamaliciousappfromaccessing
thecodeorthedataofotherapplicationsinthesystem.
Device File System
TheAudioCodes device'sfile systemis encryptedonC450HD- DBWdevices.Customers may
enforceapolicyofdeviceencryptionviaMicrosoft'scloud-basedIntuneservice.
Keystore
WithAudioCodesdevices,thecertificatekeysareencryptedonthedevicefilesystem.
Device Certificate
AudioCodesdevicesareshippedwithauniquecertificatewhichissignedbyAudioCodesRoot
CA.Networkadministratorscaninstallathird-partycertificateonthephoneinthecustomer’s
trusted environment. Network administrators should follow the following guidelines when
replacingtheexistingdevicecertificate:
■ ThedevicecertificateURLwillonlybevalidifnoSCEPserverURLispresent
- 8 -