DRAFT
© 2003 - 2005 Sipura Technology, Inc
Proprietary (See Copyright Notice on Page 2)
66
The following provides a Warm Line to a local office operator (1000) after 5 seconds, unless a 4 digit
extension is dialed by the user.
( P5 <:1000> | xxxx )
12 Provisioning
Overview
Provisioning
This section contains information regarding the steps that a network administration should take when
setting up a provisioning system for large numbers of IP telephones and/or terminal adaptors. An
additional reference document is the Sipura SPA Provisioning Guide, which provides detailed information
on provisioning requirements.
Provisioning Capabilities
The SPA-841 provides for secure provisioning and remote upgrades. The following provides an overview
of the basic functionality and requirements for provisioning IP telephones:
•
Provisioning is achieved through configuration profiles requested by the device from a
provisioning server, via TFTP, HTTP or HTTPS.
•
No end-user intervention is required to initiate or complete a profile update or firmware upgrade.
The SPA-841 is programmed to resync with the server on power-up and periodically thereafter.
•
Remote upgrade is also achieved via TFTP, HTTP or HTTPS.
•
General purpose parameters are provided as an additional aid to service providers in managing
the provisioning process. These parameters are often used to hold encryption keys, file path
locations, or provisioning state.
•
The SPA can be configured to resync its internal configuration state to a remote profile
periodically and on power up. Additional triggers are available, including SIP NOTIFY messages,
registration state, and provisioning state.
•
256-bit symmetric key encryption of profiles.
•
Supports targeted (end-point unique) key-less profile encryption.
•
The SPA 841 supports a secure first-time provisioning mechanism using SSL functionality. For
this purpose, each SPA-841 is loaded with a unique client certificate at manufacturing time. The
certificate identifies each device by MAC address, Serial Number, and Product Name. This
feature can be used in conjunction with a properly configured HTTPS provisioning server, to
provide for an additional level of security in provisioning units.
•
Profile resyncs and firmware upgrades are attempted only when the SPA is idle, as they may
trigger a software reboot, as a result of changes in parameter values. A configurable override
delay is available to force a resync after a predetermined grace period.