Find answers to your technical questions and learn how to use our products
Search suggestions:
Find answers to your technical questions and learn how to use our products
Search suggestions:
|
Feature
|
Condition to add
|
Configuration to remove
|
|---|---|---|
|
SSH
|
Always, when enabled
|
Set SSH_ALLOWED to 0
|
|
WiFi
|
Always, when enabled and WiFi chip is present
|
Set WIFISTAT to 0
or
Remove WiFi chip
|
|
SLA Monitor
|
Always, when enabled
|
Set SLMSTAT to 0
|
|
EAP-MD5
|
When EAP MD5 is enabled
|
Set DOT1XEAPS to TLS
or
Set DOT1XSTAT to 0
|
|
EAP-PEAP
|
When EAP PEAP is enabled
|
Set DOT1XEAPS to TLS
or
Set DOT1XSTAT to 0
|
|
EAP-TTLS
|
When EAP TTLS is enabled
|
Set DOT1XEAPS to TLS
or
Set DOT1XSTAT to 0
|
|
WML
|
WML Browser, when WMLPROXY value is defined with http transport or if WMLPROXY is not defined and:
|
WMLPROXY use https transport or define "" to disable this feature
WMLIDLEURL use https transport or define "" to disable this feature
WMLHOME use https transport or define "" to disable this feature
|
|
PUSH
|
Push Notification, when TPSLIST is defined with http transport.
|
TPSLIST use https transport or define "" to disable this feature
|
|
RSYSLOG
|
Remote Syslog, when not configured secure
|
Set LOGSRVR_SECURE to 1
or
Set SYSLOG_ENABLED to 0
|
|
RTP/RTCP
|
When not using SRTP
|
MEDIAENCRYPTION value does not include 9
|
|
HTTP
|
HTTPSRVR is defined or BRURI is defined using http transport
|
Set AUTH to 1
or
HTTPSRVR "" (instead use TLSSRVR)
BRURI use https transport or define "" to disable this feature
|
|
HTTP_PPM
|
In Aura mode only, when CONFIG_SERVER_SECURE_MODE is 0
|
Set CONFIG_SERVER_SECURE_MODE to 1
|
|
LDAP
|
When enabled and uses http or DIRAUTHTYPE = 1 (SASL)
|
Set DIRSECURE to 1 and DIRAUTHTYPE = 0
or
Set DIRENABLED_PLATFORM to 0
|
|
WEBSvr
|
Always, when enabled
|
Set ENABLE_WEBSERVER to 0
|
|
SIP
|
When not using SIP-TLS
|
SIP_CONTROLLER_LIST must only include transport=tls
|
|
SCEP
|
When SCEP encryption algorithm is DES or URL is defined with http
|
Set SCEPENCALG to 1 and URL is defined with https
Set SCEPENCALG_2 to 1 and URL is defined with https
Set SCEPENCALG_3 to 1 and URL is defined with https
or
Set MYCERTURL to ""
Set MYCERTURL_2 to ""
Set MYCERTURL_3 to ""
|
|
PKCS12
|
When PKCS12URL is defined with http transport
|
PKCS12URL is defined with https
PKCS12URL_2 is defined with https
PKCS12URL_3 is defined with https
or
Set PKCS12URL to ""
Set PKCS12URL_2 to ""
Set PKCS12URL_3 to ""
|
|
HELD
|
When URL is defined with http transport
|
HELD_URL use https transport or define "" to disable this feature
|
|
AADS
|
When URL is defined with http transport
|
AADS_URL use https transport or define "" to disable this feature
|
|
BRDSFT
|
When URL is defined with http transport
|
XSI_URL use https transport or define "" to disable this feature
|
|
REST
|
When URL is defined with http transport
|
REST_URL use https transport or define "" to disable this feature
|
|
EXCHANGE
|
When http is used
|
Set EXCHANGE_SERVER_SECURE_MODE to 1
|
|
Feature
|
Parameter
|
|---|---|
|
Provisioning server must use HTTPS
|
Set TLSSRVR
|
|
PPM Config Server must use HTTPS
|
Set CONFIG_SERVER_SECURE_MODE to 1
|
|
802.1x must use EAP-TLS
|
Set DOT1XEAPS to TLS
|
|
SCEP must use AES-256
|
Set SCEPENCALG to 1
|
|
PKCS12 must use HTTPS
|
Set PKCS12URL
|
|
OCSP must use HTTPS
|
Set OCSP_URI
|
|
LDAP must use TLS
|
Set DIRSECURE to 2
|
|
Syslog must use TLS
|
Set LOGSRVR_SECURE to 1
|
|
Push must use TLS
|
Set PUSH_MODE to 1
|
|
BRURI must use HTTPS
|
Set BRURI
|
|
User store must use HTTPS
|
Set USER_STORE_URI
|
|
Microsoft Exchange must use HTTPS
|
Set EXCHANGE_SERVER_SECURE_MODE to 1
|
|
WML Browser
|
Set WMLIDLEURI to Null or HTTPS
Set WMLHOME to Null or HTTPS
Set WMLPROXY to Null or HTTPS
|