EasyManuals Logo

Yealink SIP-T48G Administrator's Guide

Yealink SIP-T48G
898 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #741 background imageLoading...
Page #741 background image
Configuring Security Features
721
Step4: Server sends Change Cipher Spec message to activate the negotiated options
for all future messages it will send.
IP phones can encrypt SIP with TLS, which is called SIPS. When TLS is enabled for an
account, the SIP message of this account will be encrypted, and a lock icon appears on
the LCD screen after the successful TLS negotiation.
Certificates
The IP phone can serve as a TLS client or a TLS server. The TLS requires the following
security certificates to perform the TLS handshake:
Trusted Certificate: When the IP phone requests a TLS connection with a server, the
IP phone should verify the certificate sent by the server to decide whether it is
trusted based on the trusted certificates list. The IP phone has 30 built-in trusted
certificates. You can upload 10 custom certificates at most. The format of the trusted
certificate files must be *.pem,*.cer,*.crt and *.der and the maximum file size is
5MB. For more information on 30 trusted certificates, refer to Appendix C: Trusted
Certificates on page 794.
Server Certificate: When clients request a TLS connection with the IP phone, the IP
phone sends the server certificate to the clients for authentication. The IP phone
has two types of built-in server certificates: a unique server certificate and a
generic server certificate. You can only upload one server certificate to the IP
phone. The old server certificate will be overridden by the new one. The format of
the server certificate files must be *.pem and *.cer and the maximum file size is
5MB.
- A unique server certificate: It is unique to an IP phone (based on the MAC address)
and issued by the Yealink Certificate Authority (CA).
- A generic server certificate: It issued by the Yealink Certificate Authority (CA). Only
if no unique certificate exists, the IP phone may send a generic certificate for
authentication.
The IP phone can authenticate the server certificate based on the trusted certificates list.
The trusted certificates list and the server certificates list contain the default and custom
certificates. You can specify the type of certificates the IP phone accepts: default
certificates, custom certificates or all certificates.
Common Name Validation feature enables the IP phone to mandatorily validate the
common name of the certificate sent by the connecting server. And Security verification
rules are compliant with RFC 2818.
Note
In TLS feature, we use the terms trusted and server certificate. These are also known as
CA and device certificates.
Resetting the IP phone to factory defaults will delete custom certificates by default. But
this feature is configurable using the configuration files. For more information on the
configuration parameter, refer to Transport Layer Security on page 719.

Table of Contents

Other manuals for Yealink SIP-T48G

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Yealink SIP-T48G and is the answer not in the manual?

Yealink SIP-T48G Specifications

General IconGeneral
Expansion module supportYes
Handset typeWired handset
Product typeIP Phone
Product colorBlack
Volume control-
Display diagonal7 \
Display resolution800 x 480 pixels
Lines quantity- lines
Phonebook capacity1000 entries
Number of VoIP accounts6
AC adapter input voltage100 - 240 V
Number of handles included1 pc(s)
Weight and Dimensions IconWeight and Dimensions
Width266 mm
Height185 mm

Related product manuals