Table Of Contents
Phone Security Overview
Understanding How Security Works for Phones
Supported Phone Models
Viewing Security Settings on the Phone
Phone Security Configuration Checklist
Where to Find More Information
Phone Security Overview
This chapter contains information on the following topics:
•
Understanding How Security Works for Phones
•
Supported Phone Models
•
Viewing Security Settings on the Phone
•
Phone Security Configuration Checklist
•
Where to Find More Information
Understanding How Security Works for Phones
At installation of Cisco Unified CallManager, the Cisco Unified CallManager cluster boots up in nonsecure mode. When the phones boot up after the Cisco Unified CallManager installation, all devices register as nonsecure with Cisco Unified CallManager.
After you upgrade from Cisco Unified CallManager 4.0(1) or a later release, the phones boot up in the device security mode that you enabled prior to the upgrade; all devices register by using the chosen security mode.
The Cisco Unified CallManager 5.1 installation creates a self-signed certificate on Cisco Unified CallManager and TFTP servers. You may also choose to use a third-party, CA-signed certificate for Cisco Unified CallManager instead of the self-signed certificate. After you configure authentication, Cisco Unified CallManager uses the certificate to authenticate with supported Cisco Unified IP Phones. After a certificate exists on the Cisco Unified CallManager and TFTP servers, Cisco Unified CallManager does not reissue the certificates during each Cisco Unified CallManager upgrade. You must create a new CTL file with the new certificate entries.
Tip
For information on unsupported or nonsecure scenarios, see the "Interactions and Restrictions" section.
Cisco Unified CallManager maintains the authentication and encryption status at the device level. If all devices that are involved in the call register as secure, the call status registers as secure. If one device registers as nonsecure, the call registers as nonsecure, even if the phone of the caller or recipient registers as secure.
Cisco Unified CallManager retains the authentication and encryption status of the device when a user uses Cisco Extension Mobility. Cisco Unified CallManager also retains the authentication and encryption status of the device when shared lines are configured.
Tip
When you configure a shared line for an encrypted Cisco Unified IP Phone, configure all devices that share the lines for encryption; that is, ensure that you set the device security mode for all devices to encrypted by applying a security profile that supports encryption.
Supported Phone Models
This security document does not list the security features that are supported on your Cisco Unified IP Phone. For a list of security features that are supported on your phone, refer to the phone administration and user documentation that supports this Cisco Unified CallManager release or the firmware documentation that supports your firmware load.
Although you may be able to configure the security features in Cisco Unified CallManager Administration, the features may not work until you install a compatible firmware load on the Cisco TFTP server.
Viewing Security Settings on the Phone
You can configure and view certain security-related settings on phones that support security; for example, you can view whether a phone has a locally significant certificate or manufacture-installed certificate installed. For additional information on the security menu and icons, refer to the Cisco Unified IP Phone administration and user documentation that supports your phone model and this version of Cisco Unified CallManager.
When Cisco Unified CallManager classifies a call as authenticated or encrypted, an icon displays on the phone to indicate the call state. To determine when Cisco Unified CallManager classifies the call as authenticated or encrypted, refer to the "Security Icons" section and the"Interactions and Restrictions" section.
Phone Security Configuration Checklist
Table 4-1 describes the tasks to configure security for supported phones.
Where to Find More Information
Related Topics
•
Interactions and Restrictions
•
Authentication, Integrity, and Authorization Overview
•
Encryption Overview
•
Configuration Checklist Overview
•
Using the Certificate Authority Proxy Function
•
Phone Security Configuration Checklist
•
Configuring a Phone Security Profile
•
Configuring Encrypted Phone Configuration Files
•
Phone Hardening
Related Cisco Documentation
•
Cisco Unified IP Phone Administration Guide for Cisco Unified CallManager
•
Cisco Unified CallManager Troubleshooting Guide