Version 6.2
675
February 2011
SIP User's Manual
12. Configuration Parameters Reference
Parameter
Description
the client certificate to establish the TLS connection.
Notes:
For this parameter to take effect, a device reset is required.
The SIPS certificate files can be changed using the
parameters HTTPSCertFileName and
HTTPSRootFileName.
Web/EMS: Peer Host Name
Verification Mode
[PeerHostNameVerificationMode]
Determines whether the device verifies the Subject Name of a
remote certificate when establishing TLS connections.
[0]
Disable = Disable (default).
[1]
Server Only = Verify Subject Name only when acting as
a server for the TLS connection.
[2]
Server & Client = Verify Subject Name when acting as a
server or client for the TLS connection.
When a remote certificate is received and this parameter is not
disabled, the value of SubjectAltName is compared with the list
of available Proxies. If a match is found for any of the
configured Proxies, the TLS connection is established.
The comparison is performed if the SubjectAltName is either a
DNS name (DNSName) or an IP address. If no match is found
and the SubjectAltName is marked as ‘critical’, the TLS
connection is not established. If DNSName is used, the
certificate can also use wildcards (‘*’) to replace parts of the
domain name.
If the SubjectAltName is not marked as ‘critical’ and there is no
match, the CN value of the SubjectName field is compared with
the parameter TLSRemoteSubjectName. If a match is found,
the connection is established. Otherwise, the connection is
terminated.
Web: TLS Client Verify Server
Certificate
EMS: Verify Server Certificate
[VerifyServerCertificate]
Determines whether the device, when acting as a client for TLS
connections, verifies the Server certificate. The certificate is
verified with the Root CA information.
[0]
Disable (default).
[1]
Enable.
Note:
If Subject Name verification is necessary, the parameter
PeerHostNameVerificationMode must be used as well.
Web/EMS: TLS Remote Subject
Name
[TLSRemoteSubjectName]
Defines the Subject Name that is compared with the name
defined in the remote side certificate when establishing TLS
connections.
If the SubjectAltName of the received certificate is not equal to
any of the defined Proxies Host names/IP addresses and is not
marked as 'critical', the Common Name (CN) of the Subject field
is compared with this value. If not equal, the TLS connection is
not established. If the CN uses a domain name, the certificate
can also use wildcards (‘*’) to replace parts of the domain
name.
The valid range is a string of up to 49 characters.
Note:
This parameter is applicable only if the parameter
PeerHostNameVerificationMode is set to 1 or 2.
Summary of Contents for Mediant 800 MSBG
Page 2: ......
Page 366: ...SIP User s Manual 366 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 372: ...SIP User s Manual 372 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 390: ...SIP User s Manual 390 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 404: ...SIP User s Manual 404 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 616: ...SIP User s Manual 616 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 636: ...SIP User s Manual 636 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 652: ...SIP User s Manual 652 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...
Page 886: ...SIP User s Manual 886 Document LTRT 12804 Mediant 800 MSBG Reader s Notes ...