CHAPTER1 Overview
C470HD | Users & Administrator's Manual
Device File System
TheAudioCodesdevice'sfilesystemisencryptedonC470HDdevices.Customersmayenforcea
policyofdeviceencryptionviaMicrosoft'scloud-basedIntuneservice.
Keystore
WithAudioCodesdevices,thecertificatekeysareencryptedonthedevicefilesystem.
Device Certificate
AudioCodesdevicesareshippedwithauniquecertificatewhichissignedbyAudioCodesRoot
CA.Networkadministratorscaninstallathird-partycertificateonthephoneinthecustomer’s
trusted environment. Network administrators should follow the following guidelines when
replacingtheexistingdevicecertificate:
■ ThedevicecertificateURLwillonlybevalidifnoSCEPserverURLispresent
■ Usethefollowingtwoparameterstosetthedevicecertificateinthephone'sconfiguration
file:
● security/device_certificate_url=http://<server-ip>/device.crt
● security/device_private_key_url=http://<server-ip>/device.key
Trusted certificates are provisioned by parameter security/ca_certificate/[0-4]/
Data Protection
AudioCodesdevicesrunAndroidwhichhasintegralproceduresforprotectingandsecuringuser
data.
Debugging Interface
■ AudioCodesdevicesleverageSSHasadebugginginterface.
■ AudioCodesrecommendsthatcustomersdisableSSHondevicesviaAudioCodes'Device
Manager(OVOC).
■ AudioCodesrecommendschangingtheAdminpasswordfromthedefault,viatheTeams
AdminCenterorAudioCodes'DeviceManager(OVOC).
■ Whenadevice-ormultipledevices-needstobedebugged,userscanenableSSHonit/
them,accessSSHwiththenewAdminpasswordforthedebuggingphase,anddisableSSH
oncedebuggingisfinished.
SSH is by default disabled and can be enabled with Administrator permissions in the
phone screen (Device Administration > Debugging > SSH).
- 8 -