Specifications

Phone Hardening Measures
A31003-D3000-P100-01-76A9, 10-2013
16 OpenStage and Desk Phone IP SIP V3, Security Checklist, Planning Guide
Secure Administration Access to the Phone
Setting communication between phone and DLS to “secure mode”
"Secure mode" offers mutual authentication between DLS and the phone. The
connection between DLS and phone will be established, if DLS has successfully
authenticated the phone and vice versa. Secure mode with or without PIN
(Personal Identification Number) will be set by the DLS. The PIN has to be
inputted at the phone when requested. “Secure mode with PIN” protects the
transfer of the key material and should be preferred. Us-age of Secure mode
without PIN may offer an attacker to capture the key material and may get non-
authorized access to the DLS and phone.
Prerequisites for the usage of the secure mode are the following:
Customer specific key material has to be created, e.g. with customers own CA
or with openSSL or other tool. Provided by customer.
The key material is distributed by DLS to phones in default mode (in customer
network or preconfigured). The distribution of keys and certificates via DLS
(Deployment Service) is depicted in the Deployment Service Admin Guide,
chapter " Automatic Certificate Deployment"
Both, phones as well as DLS have to be set to "secure mode" How to
configure the secure mode for phone is described in: "IP Device Configu-
ration"
Table: Secure Communication with DLS Servert
Related Topics
CL-Secure DLS Access
Measures If using Default mode ensure that the DLS address is
provided by the DHCP
For improved security use secure mode between DLS
and Phone
References See Phone Administration Manual chapters on Vendor Spe-
cific: VLAN Discovery and DLS Address and How to Use
Option #43 “Vendor Specific”
See DLS manual Configuration & Update Service (DLS)
Can be done via
Needed Access Rights Administrator Access
Executed
Provide DLS IP address
from DHCP
Yes No:
Setup Secure mode for
DLS –Phone communica-
tions
Yes No
Customer Comments and
Reasons