Cisco SRP521W-K9-G1 Administration Guide - Page 112

Secure Call Details, Encrypted Master Key 16B or 128b

Page 112 highlights

6 Configuring Voice Configuring Dial Plans The signing agent is implicit and must be the same for all devices that communicate securely with each other. The public key of the signing agent is preconfigured into the SRP by the administrator and is used by the SRP to verify the Mini-Certificate of its peer. The Mini-Certificate is valid if it has not expired, and it has a valid signature. The SRP can be configured so that, by default, all outbound calls are either secure or not secure. If secure by default, the user has the option to disable security when making a call by dialing *19 before dialing the target number. If not secure by default, the user can make a secure outbound call by dialing *18 before dialing the target number. However, the user cannot force inbound calls to be secure or not secure; that depends on whether the caller has security enabled or not. The SRP will not switch to secure mode if the CID of the called party from its MiniCertificate does not agree with the user-id used in making the outbound call. The SRP performs this check after receiving the Mini-Certificate of the called party. Secure Call Details Looking at the second stage of setting up a secure call in greater detail, this stage can be further divided into two steps. STEP 1 The caller sends a "Caller Hello" message (base64 encoded and embedded in the message body of a SIP INFO request) to the called party with the following information: • Message ID (4B) • Version and flags (4B) • SSRC of the encrypted stream (4B) • Mini-Certificate (252B) Upon receiving the Caller Hello, the called party responds with a Callee Hello message (base64 encoded and embedded in the message body of a SIP response to the caller's INFO request) with similar information, if the Caller Hello message is valid. The caller then examines the Callee Hello and proceeds to the next step if the message is valid. STEP 2 The caller sends the "Caller Final" message to the called party with the following information: • Message ID (4B) • Encrypted Master Key (16B or 128b) 112 Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models)

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229

Configuring Voice
Configuring Dial Plans
112
Cisco SRP500 Series Services Ready Platforms Administration Guide (SRP520 Models)
6
The signing agent is implicit and must be the same for all devices that
communicate securely with each other. The public key of the signing agent is pre-
configured into the SRP by the administrator and is used by the SRP to verify the
Mini-Certificate of its peer. The Mini-Certificate is valid if it has not expired, and it
has a valid signature.
The SRP can be configured so that, by default, all outbound calls are either secure
or not secure. If secure by default, the user has the option to disable security when
making a call by dialing *19 before dialing the target number. If not secure by
default, the user can make a secure outbound call by dialing *18 before dialing the
target number. However, the user cannot force inbound calls to be secure or not
secure; that depends on whether the caller has security enabled or not.
The SRP will not switch to secure mode if the CID of the called party from its Mini-
Certificate does not agree with the user-id used in making the outbound call. The
SRP performs this check after receiving the Mini-Certificate of the called party.
Secure Call Details
Looking at the second stage of setting up a secure call in greater detail, this stage
can be further divided into two steps.
STEP 1
The caller sends a “Caller Hello” message (base64 encoded and embedded in the
message body of a SIP INFO request) to the called party with the following
information:
Message ID (4B)
Version and flags (4B)
SSRC of the encrypted stream (4B)
Mini-Certificate (252B)
Upon receiving the Caller Hello, the called party responds with a Callee Hello
message (base64 encoded and embedded in the message body of a SIP
response to the caller’s INFO request) with similar information, if the Caller Hello
message is valid. The caller then examines the Callee Hello and proceeds to the
next step if the message is valid.
STEP
2
The caller sends the “Caller Final” message to the called party with the following
information:
Message ID (4B)
Encrypted Master Key (16B or 128b)