IP Phone User Manual
Grandstream Networks, Inc.  XML Provisioning Guide  Page 5 of 5 
www.grandstream.com    Last Updated: 7/2011 
SECURE PROVISIONING 
Although the XML config file can be encrypted and the encryption algorithm itself is regarded as safe and 
strong by using AES with 256-bit key length, it remains a question on how to bootstrap and provision the 
initial XML encryption password. There are several methods to provide solutions to this: 
1.  Use legacy binary config file to set the initial XML encryption password. The legacy binary file is 
encrypted and it generally regarded safe. 
2.  Use HTTPS and use client side authentication. This is the industry standard approach and has 
the strongest safety.





