Configuring DTLS policy to secure communications between phones and Device Adapter cluster

Last Updated : Feb 18, 2020 |
Prolog information
Note:
Mutual DTLS authentication is supported only on the 11xx and 12xx IP UNIStim phones. If the Device Adapter cluster contains any other phone; for example, 200x IP UNIStim phone, then do not enable client authentication.
If you set the Enable client authentication attribute to Yes, then you must install the Client Identity Certificate on the 11xx and 12xx IP UNIStim phones. During registration, the IP phones send this certificate to Device Adapter for mutual authentication.
The 11xx and 12xx series IP phones are FIPS 140-2 compliant. Ensure that the Client Identity Certificates that are installed on these phones have a key length of at least 2048 bit. This is required for the FIPS compliance process.
You can install the Client Identity Certificate on the 11xx and 12xx UNIStim phones by doing any of the following:
  • Use SCEP.
  • Download the PKCS#12 file that is specified in the [DEV_CERT] configuration section of the UNIStim Software Release 4.3 for IP Deskphones Release notes.
For more information about installing the Client Identity Certificate on the 11xx and 12xx UNIStim phones, see the UNIStim Software Release 4.3 for IP Deskphones Release notes.
  1. Log on to System Manager by using administrative credentials.
  2. Navigate to ElementsAvaya Breeze®Configuration.
  3. Click Attributes.
  4. Depending on whether you want to configure the DTLS policy at a cluster level or a global level, do one of the following:
    • Click the Service Clusters tab, select the cluster, and then select the service as DeviceAdapter.
    • Click the Service Global tab and select the service as DeviceAdapter.
  5. On the Attributes Configuration page, navigate to the IP Telephony Node / DTLS group.
  6. To override the default value of an attribute, select the Override Default check box corresponding to the attribute.
  7. In the DTLS policy field, in Effective Value, click the DTLS policy that you want to use to secure communications between phones and Avaya Breeze® platform cluster where the Device Adapter snap-in is deployed.
  8. In the Enable client authentication field, in Effective Value, click Yes to enable client authentication.
  9. Click Commit.