Description
Feature
Each Cisco Unified IP Phone contains a unique manufacturing installed
certificate (MIC), which is used for device authentication. The MIC is a
permanent unique proof of identity for the phone, and allows Cisco Unified
Communications Manager to authenticate the phone.
Manufacturing installed
certificate
After you configure an SRST reference for security and then reset the
dependent devices in Cisco Unified Communications Manager
Administration, the TFTP server adds the SRST certificate to the phone
cnf.xml file and sends the file to the phone. A secure phone then uses a
TLS connection to interact with the SRST-enabled router.
Secure SRST reference
Uses Secure Real-time Transport Protocol (SRTP ) to ensure that the media
streams between supported devices prove secure and that only the intended
device receives and reads the data. Includes creation of a media master key
pair for the devices, delivery of the keys to the devices, and securing the
key delivery while the keys are in transport.
Media encryption
Ensures that all SCCP and SIP signaling messages that are sent between
the device and the Cisco Unified Communications Manager server are
encrypted.
Signaling encryption
Implements parts of the certificate generation procedure that are too
processing-intensive for the phone, and interacts with the phone for key
generation and certificate installation. The CAPF can be configured to
request certificates from customer-specified certificate authorities on behalf
of the phone, or it can be configured to generate certificates locally.
CAPF (Certificate Authority
Proxy Function)
Defines whether the phone is nonsecure, authenticated, encrypted, or
protected.
Security profiles
Ensures the privacy of phone configuration files.
Encrypted configuration files
Prevents access to a phone web page, which displays a variety of operational
statistics for the phone.
Optional disabling of the web
server functionality for a phone
Cisco Unified IP Phone 7975G, 7971G-GE, 7970G, 7965G, and 7945G Administration Guide for Cisco Unified
Communications Manager 9.0 (SCCP and SIP)
16
Cisco Unified IP Phone
Supported Security Features