19.08.2013 Views

RMX 2000 Administrator's Guide Version 7.6.1 - Polycom

RMX 2000 Administrator's Guide Version 7.6.1 - Polycom

RMX 2000 Administrator's Guide Version 7.6.1 - Polycom

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Offline Certificate Validation<br />

Appendix F-Secure Communication Mode<br />

Offline Certificate Validation has been enhanced to include the following rules and<br />

procedures:<br />

Peer Certificates<br />

The diagram below illustrates the peer certificate validation procedure.<br />

• The credentials of each certificate received from a networked peer are verified against a<br />

repository of trusted certificates. (Each networked entity contains a repository of<br />

trusted certificates.)<br />

• The digital signature of the certificate’s issuing authority is checked along with the<br />

certificate’s validity (expiration date).<br />

Self Validation of Certificates<br />

• The DNS name field in the entity’s certificate is checked for a match with the entity’s<br />

DNS name.<br />

• The date of the <strong>RMX</strong>’s certificate is checked for validity during power-up and when<br />

connecting to management applications (<strong>RMX</strong> Web Client and <strong>RMX</strong> Manager).<br />

Certificate Revocation List<br />

• Each certificate received from a networked peer is verified against a repository of<br />

revoked certificates. (Each networked entity contains a repository of revoked<br />

certificates.<br />

• Revocation certificates are checked against a list of trusted issuers.<br />

• The digital signature of the issuing authority of the revocation certificate is verified.<br />

Installing and Using Certificates on the <strong>RMX</strong><br />

The following certificate file formats are supported:<br />

• PEM<br />

• DER<br />

• PKCS#7/P7B<br />

• PKCS#12PFX<br />

<strong>Polycom</strong>, Inc. F-9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!