I use TLS and SRTP on my Asterisk servers. The server certificates are signed 
by my internal CA, and the Root CA cert is distributed to the phones and soft 
phones so they will trust the server without warning. 

It is not clear to me if Asterisk can be configured to actually reject client 
connections/registrations from peers which do not possess a client certificate 
which has been signed by a particular CA ?

If so, could it be such that the common name in the client certificate would 
need to match the username or Asterisk “extension” ?


I’m wondering if this can be done ,  to have a second factor of authentication 
besides the SIP secret , since in my current setup, despite using a TLS/SSL 
cert for the server, the server only verifies the client by the SIP secret.

Regards,

Kevin Long

Attachment: smime.p7s
Description: S/MIME cryptographic signature

-- 
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --
New to Asterisk? Join us for a live introductory webinar every Thurs:
               http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-users

Reply via email to