g. Clear the phone and then restart the phone, and ensure that the phone upgrades to
the latest firmware available.
h. Connect the phone to a network that supports DOT1x.
The phone starts the process of certificate enrollment automatically, by sending a
SCEP request to MYCERTURL. After the boot process completes, the phone obtains
the root certificate and the device certificate successfully and changes to the EAP-
TLS mode.
Note:
When you install the identity certificate using SCEP, you can download the
PKCS12 file.
i. Monitor the CA, to check that all phones that you have upgraded, have enrolled their
certificates with the CA. If you administer the CA to require manual approval of
certificate enrollment requests, then the phone will take a minimum of two minutes to
download the enrolled certificate after the CA approves the request. Therefore, do not
restart the phones until at least 2 minutes after approving the certificate enrollment
request. If the certificate enrollment process is automatic, it takes less time than
manual enrollment.
3. Administer the RADIUS server to accept the identity certificates provided by the phones.
4. To turn on 802.1x authentication, change the 46xxsettings.txt file by setting DOT1XSTAT to
a value of 1 or 2.
5. Restart the phones to apply the new settings. The phones start their supplicants with the
EAP-TLS authentication method. Configure the Layer 2 switches to which you attach these
phones. The switches can then support EAP-TLS on those ports to which you attach the
phones.
If you do not require the phone to connect to a network that does not support DOT1X ,
reset the phones manually or using the CM and only then, change the switch configuration
to support EAP-TLS.
Result
The switches then prompt the phones to authenticate using EAP-TLS and the phones must
authenticate themselves using the enrolled certificates. After you setup the phones, the phones
must maintain their configurations across restarts and upgrades. Depending on the value of
MYCERTRENEW, the phones try to renew their certificates enrollment, periodically. The
administrator must monitor pending enrollments.
Related links
EAP-TLS support for authentication on page 105
Administering Deskphone Options
March 2018 Administering Avaya 9608/9608G/9611G/9621G/9641G/9641GS IP Deskphones H.
323 108
Comments on this document? infodev@avaya.com