
EAP Re-authentication
The re-authentication process proceeds in the background without disturbing the ongoing
operation of the IP Deskphone. If the re-authentication fails or times out, the IP Deskphone
becomes inoperable. Re-authentication interval is controlled by the Layer 2 switch re-
authentication interval parameter. The minimum supported re-authentication interval when
EAP-MD5 and EAP-PEAP are configured is 10 seconds; for EAP-TLS, the minimum interval
is 20 seconds.
Provisioning configuration file download
Securely download provisioning configuration files through HTTPS.
Provisioning configuration files download through HTTPS
The IP Deskphone can contact a provisioning server and download an 12xxSIP.cfg file to
identify additional files and protocols used. When a file is identified, and the protocol specified
in the "protocol" parameter is HTTPS, the IP Deskphone contacts the target server and
negotiates a TLS connection. Then, the IP Deskphone downloads the specified file and
terminates the connection.
HTTP connection over TLS is established by using single or mutual authentication.
Single Authentication
A server certificate, user name, and password are required to establish TLS connection
between the IP Deskphone and the provisioning server. The server certificate must be signed
by a certificate authority. The IP Deskphone uses the server certificate to validate the identity
of the provisioning server that the IP Deskphone is connected to; the provisioning server uses
the user name and password to authenticate the IP Deskphone. The IP Deskphone must be
preloaded with the root certificate used in signing the server certificate. The root certificate is
downloaded to the IP Deskphone by connecting to a provisioning server through EAP-MD5,
and using one of the insecure protocols supported by the IP Deskphone, such as HTTP, TFTP
or FTP. EAP-MD5 ensures that the connection between the IP Deskphone and the provisioning
server is secure. The user name and password are required to authenticate the IP Deskphone
to the provisioning server and must be loaded in a secure manner before the IP Deskphone
establishes the HTTPS connection with the provisioning server. There is no mechanism for
EAP Re-authentication
SIP Software for Avaya 1200 Series IP Deskphones-Administration January 2012 225
Komentarze do niniejszej Instrukcji