Securing IP Office Manager

Last Updated : Apr 20, 2022 |
Prolog information
  1. Apply the following configuration settings in IP Office Manager using the FilePreferencesSecurity tab to ensures more secure IP Office communications and help keep configuration data away from unauthorized users:
    ADDITIONAL INFORMATION:
    Configuration
    Parameter Settings
    Request Login on Save
    Enabled
    Close Configuration/Security Settings After Send
    Enabled
    Save Configuration File After Load
    Disabled
    Backup Files on Send
    Disabled
    Enable Application Idle Timer (5 minutes)
    Enabled
    Secure Communications
    Enabled
  2. The Manager Certificate Checks on the FilePreferencesSecurity tab should be set according to the security policy. It should be set to None only for recovery purposes.
  3. For more information see Certificates and Trust and Windows Certificate Management.
  4. If mutual certificate authentication is required (that is, the IP Office configuration or security administration service will request a certificate from IP Office Manager) the FilePreferencesSecurityCertificate offered to IP Office needs to be set with an identity certificate. If Current User is selected, it will only apply the current Windows user. If Local Machine is selected, it will be used for all Windows users of that PC.
  5. To prevent other administrators from modifying the FilePreferencesSecurity tab settings, ensure those Service Users do not have the rights to edit security settings, or have the Administrator Manager Operator Role.
  6. In IP Office Manager's FilePreferencesDirectories tab, change the Working Directory to be different to the Binary Directory. If the two directory settings are the same, it potentially allows remote TFTP/HTTP file access to the folder containing copies of configuration files.
  7. Ensure all offline configuration files, exported files or other configuration data are controlled.