Mitel 6800 Series SIP Phone Release 4.2.0 Administrator Guide
4-37
•
TLS 1.0
•
SSL 3.0
3.
Enable HTTP to HTTPS redirect by checking the
HTTPS Server - Redirect HTTP to
HTTPS
field check box. (Disable this field by unchecking the check box). Default is disabled.
4.
Enable the blocking of XML HTTP POSTs by the HTTPS server by checking the
HTTPS
Server - Block XML HTTP POSTs
field check box. (Disable this field by unchecking the
check box). Default is disabled.
5.
Click
Save Settings
to save your settings.
HTTPS LOCAL CERTIFICATE SUPPORT/MUTUAL AUTHENTICATION
The 6800 series IP phones provide a built-in common 2048-bit HTTPs certificate allowing for
mutual authentication between the HTTPs server and the phones during an HTTPs session.
The certificate can be used for file download processes (e.g. configuration file download for
secure provisioning) and for HTTPs/XML requests. Please go to
www.miteldocs.com
to obtain
the client certificate.
HTTPS SERVER CERTIFICATE VALIDATION
The HTTPS client on the IP Phones support validation of HTTPS certificates. This feature
supports the following:
•
Comodo (EssentialSSL and 4096-bit RSA), CyberTrust, DigiCert, Entrust, GoDaddy, Geo-
Trust, Mitel MiVoice Border Gateway (MBG), Symantec (Class 3 Secure Server CA - G4),
Thawte, TrustZone, or Verisign signed certificates
•
User-provided certificates
•
Checking of hostnames
•
SSL Wildcard certificate (i.e. SSL certificate specifying the Common Name as a wildcard
[e.g. CN=*.company.com]) support.
•
Checking of certificate expiration
•
Ability to disable any or all of the validation steps
•
Phone displays a message when a certificate is rejected (except on check-sync operations)
All validation options are enabled by default.
Certificate Management
Mitel Provided Certificates
The phones come with root certificates from Comodo (EssentialSSL and 4096-bit RSA),
CyberTrust, DigiCert, Entrust, GoDaddy, GeoTrust, Mitel MBG, Symantec (Class 3 Secure
Server CA - G4), Thawte, TrustZone, or Verisign pre-loaded.
User Provided Certificates
The administrator has the option to upload their own certificates onto the phone. The phone
downloads these certificates in a file of .PEM format during boot time after configuration
Summary of Contents for 6867i Premium
Page 1: ...Mitel 6800 Series SIP Phones 58014473 REV00 RELEASE 4 2 0 ADMINISTRATOR GUIDE ...
Page 21: ...Chapter 1 OVERVIEW ...
Page 52: ...Chapter 2 CONFIGURATION INTERFACE METHODS ...
Page 71: ...Chapter 3 ADMINISTRATOR OPTIONS ...
Page 154: ...Chapter 4 CONFIGURING NETWORK AND SESSION INITIATION PROTOCOL SIP FEATURES ...
Page 262: ...Chapter 5 CONFIGURING OPERATIONAL FEATURES ...
Page 579: ...Chapter 6 CONFIGURING ADVANCED OPERATIONAL FEATURES ...
Page 654: ...Chapter 7 ENCRYPTED FILES ON THE IP PHONE ...
Page 660: ...Chapter 8 UPGRADING THE FIRMWARE ...
Page 669: ...Chapter 9 TROUBLESHOOTING ...
Page 699: ...Appendix A CONFIGURATION PARAMETERS ...
Page 1003: ...Appendix B CONFIGURING THE IP PHONE AT THE ASTERISK IP PBX ...
Page 1007: ...Appendix C SAMPLE CONFIGURATION FILES ...
Page 1023: ...Appendix D SAMPLE BLF SOFTKEY SETTINGS ...
Page 1027: ...Appendix E SAMPLE MULTIPLE PROXY SERVER CONFIGURATION ...
Page 1042: ......