Users Manual

SME VOIP SYSTEM GUIDE 1.1 107 | P a g e
Proprietary and Confidential
10.2 System security support details
TLS 1.2
The base station supports TLS 1.2 with the following algorithms:
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
TLS_DHE_RSA_WITH_AES_256_CBC_SHA
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
TLS_DHE_RSA_WITH_AES_128_CBC_SHA
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_128_CBC_SHA
The base station’s provided server services is limited to the following:
TLS_RSA_WITH_AES_256_CBC_SHA256
TLS_RSA_WITH_AES_128_CBC_SHA256
TLS_RSA_WITH_AES_256_CBC_SHA
TLS_RSA_WITH_AES_128_CBC_SHA
SRTP
SRTP is supported according to RFC 3711 and RFC4568 with the following two crypto suites:
AES_CM_128_HMAC_SHA1_32
AES_CM_128_HMAC_SHA1_80
DECT
In terms of DECT, the following is supported:
DECT Standard Authentication Algorithm (DSAA)
DECT encryption services with the DECT Standard Cipher (DSC) with a 35-bit initialization vector and encrypting the
voice stream with 64-bit encryption
Certificate support
DER encoded binary X.509 RSA 0-4096 bit (SHA-1 or SHA-256) certificates.
HTTPS
HTTPS can be used for:
Management transfer protocol
FWU download
Configuration download
Build in webserver.