Contact us versione Italiana
You are in: Security > Security protocols > SIP/TLS
clear
Add to favorites: save   Share: Share with facebook Share with twitter Share with myspace Share with google Share with delicious Share with digg Share with linkedin Share with reddit Share with oknotizie Share with blinklist Share with ziczac Share with technorati Share with livecom Share with yahoo Share with alice Share with upnews

Tell a friend

Your name*
Recipient email*
Your message
send
Sending ...
Your email has been sent
clear

  • Reserved area
 

SIP/TLS

SIP signaling communication over TLS provides a great value: it hides access to any sensitive information about secure phone calls from any unauthorized third party. It provides the SIP client to connect to the SIP server, that’s, allowing him to listen for inbound connection with a TLS (IETF standard 5246) protected socket by using an X509v3 digital certificate (IETF standard 5280).

It is up to the client to verify that the certificate and hostname to which it is connecting to are valid. To protect from “Man in the Middle” attacks, it is highly relevant to use always the certificates that are released and properly configured by a known certification authority.

It works exactly like HTTPS that we use daily on a secure webmail access or online banking access, meaning that the overall security model of SIP/TLS is based on the digital certificate verification process.

The detailed steps of the TLS protocol handshake are described below:

N.B.: PrivateWave strongly discourages the use of self-signed digital certificates. PrivateWave requires customers to use trusted certification authority released certificates (such as Verisign) or their own PKI (Public Key Infrastructure). It can be later added to the mobile phones the Root Certification Authority certificate in order to verify the TLS secured SIP connection.

 

clear

clear
© Copyright 2005,2012 - PrivateWave Italia S.p.A - P.IVA: 04915220968 - All rights reserved - powered by SOFTFOBIA
clear