Cisco 7971G-GE Administration Guide - Page 64

Configuring Security on the Cisco Unified IP Phone

Page 64 highlights

Configuring Security on the Cisco Unified IP Phone Chapter 3 Setting Up the Cisco Unified IP Phone • DNS server IP address Collect this information and see the instructions in Chapter 4, "Configuring Settings on the Cisco Unified IP Phone." Configuring Security on the Cisco Unified IP Phone The security features protect against several threats, including threats to the identity of the phone and to data. These features establish and maintain authenticated communication streams between the phone and the Cisco Unified Communications Manager server, and digitally sign files before they are delivered. For more information about the security features, see the "Understanding Security Features for Cisco Unified IP Phones" section on page 1-8. Also, refer to Cisco Unified Communications Manager Security Guide. A Locally Significant Certificate (LSC) installs on phones after you perform the necessary tasks that are associated with the Certificate Authority Proxy Function (CAPF). You can use Cisco Unified Communications Manager Administration to configure an LSC, as described in Cisco Unified Communications Manager Security Guide. Alternatively, you can initiate the installation of an LSC from the Security Configuration menu on the phone. This menu also lets you update or remove an LSC. Before you begin, make sure that the appropriate Cisco Unified Communications Manager and the CAPF security configurations are complete: • The CTL file should have a CAPF certificate. • The CAPF certificate must exist in the /usr/local/cm/.security/certs folder in every server in the cluster. • The CAPF is running and configured. Refer to Cisco Unified Communications Manager Security Guide for more information. To configure an LSC on the phone, perform the following procedure. Depending on how you have configured the CAPF, this procedure installs an LSC, updates an existing LSC, or removes an existing LSC. Procedure Step 1 Obtain the CAPF authentication code that was set when the CAPF was configured. Step 2 From the phone, press the Settings > Security Configuration. Note You can control access to the Settings Menu by using the Settings Access field in the Cisco Unified Communications Manager Administration Phone Configuration window. For more information, see Cisco Unified Communications Manager Administration Guide. Step 3 Press **# to unlock settings on the Security Configuration menu. (See the "Unlocking and Locking Options" section on page 4-3 for information about using locking and unlocking options.) Note If a Settings Menu password has been provisioned, SIP phones present an "Enter password" prompt after you enter **#. 3-12 Cisco Unified IP Phone 7970G/7971G-GE Administration Guide for Cisco Unified Communications Manager 7.0 OL-15299-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219

3-12
Cisco Unified IP Phone 7970G/7971G-GE Administration Guide for Cisco Unified Communications Manager 7.0
OL-15299-01
Chapter 3
Setting Up the Cisco Unified IP Phone
Configuring Security on the Cisco Unified IP Phone
DNS server IP address
Collect this information and see the instructions in
Chapter 4, “Configuring Settings on the Cisco
Unified IP Phone.”
Configuring Security on the Cisco Unified IP Phone
The security features protect against several threats, including threats to the identity of the phone and to
data. These features establish and maintain authenticated communication streams between the phone and
the Cisco Unified Communications Manager server, and digitally sign files before they are delivered.
For more information about the security features, see the
“Understanding Security Features for Cisco
Unified IP Phones” section on page 1-8
. Also, refer to
Cisco Unified Communications Manager Security
Guide
.
A Locally Significant Certificate (LSC) installs on phones after you perform the necessary tasks that are
associated with the Certificate Authority Proxy Function (CAPF). You can use
Cisco Unified Communications Manager Administration to configure an LSC, as described in
Cisco Unified Communications Manager Security Guide
.
Alternatively, you can initiate the installation of an LSC from the Security Configuration menu on the
phone. This menu also lets you update or remove an LSC.
Before you begin, make sure that the appropriate Cisco Unified Communications Manager and the
CAPF security configurations are complete:
The CTL file should have a CAPF certificate.
The CAPF certificate must exist in the /usr/local/cm/.security/certs folder in every server in the
cluster.
The CAPF is running and configured.
Refer to
Cisco Unified Communications Manager Security Guide
for more information.
To configure an LSC on the phone, perform the following procedure. Depending on how you have
configured the CAPF, this procedure installs an LSC, updates an existing LSC, or removes an existing
LSC.
Procedure
Step 1
Obtain the CAPF authentication code that was set when the CAPF was configured.
Step 2
From the phone, press the
Settings > Security Configuration
.
Note
You can control access to the Settings Menu by using the Settings Access field in the
Cisco Unified Communications Manager Administration Phone Configuration window. For
more information, see
Cisco Unified Communications Manager Administration Guide
.
Step 3
Press
**#
to unlock settings on the Security Configuration menu. (See the
“Unlocking and Locking
Options” section on page 4-3
for information about using locking and unlocking options.)
Note
If a Settings Menu password has been provisioned, SIP phones present an “Enter password”
prompt after you enter **#.