On Wed, 2009-06-17 at 16:32 -0400, Paul Mossman wrote: > I wrote: > > While looking into XX-5417 I did some prototyping and > > thinking about how to get where we eventually want to be. > > That is to have phones load their configuration over HTTPS, > > and with authentication. A rough draft proposal is below. > > I'm going to try and squeeze this into 4.2, under XX-5838: Add > provisioning of phones with HTTPS and authentication. > > Focus will be on the following phones: > - Bria Professional > - SNOM > - LG-Nortel 68xx > - Nortel IP 12x0 > - Polycom SoundPoint IP > > My plan is to decommission the current SNOM provisioning URL, so > existing deployments will need to manually reconfigure each phone upon > upgrade.
Isn't there some way we could redirect the old URLs to the new one? > The existing FTP and TFTP mechanism will be kept for now, but the plan > will be to phase them out eventually. > > I also hope to add a new CounterPath Bria provisioning URL: > https://<server>/<serial#> This will be more secure (no VM PIN sent in > cleartext). It will also allow a single account to use multiple Bria > profiles, which is not currently possible. But this URL can't be put > into DHCP, so we'll maintain the current URL too. Is there no way to put some additional path into that URL? https://<server>/profile/bria/<serial#> or something? > To make use of the new HTTPS provisioning, a phone will need to be: > - loaded with the (self-signed) Trusted CA certificate from the sipXecs > server; and > - configured with the User and PIN credentials. > > All the above phones use a different mechanism for loading certificates. > All will be supported, and there'll be a new "View" screen under System > -> Web Certificates to assist. _______________________________________________ sipx-dev mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-dev Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev sipXecs IP PBX -- http://www.sipfoundry.org/
