cucm and ip phones
lytboris at yandex-team.ru
Mon Sep 25 14:06:30 CEST 2017
Cisco IP phones (all modern) have Manufacturer Installed Certificate (MIC) so you can authenticate them using EAP-TLS.
You need to import their crcam* cert chains into your FreeRADIUS installation from https://www.cisco.com/security/pki/
On 25.09.2017 14:52, Vacheslav wrote:
> Peace, I configured my ip phones to use mab, but I read that with Radius it is possible to authenticate capable ip phones with tls.
> I searched the internet on how to do it but found almost nothing.
> Should I import the created self signed certificates from the freeradius server to the cucm? Or is that I have to export the cucm certificates to the cert directory of the freeradius server?
> Anyone has experience in configuring cucm with dot1x?
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
+7 (495) 739 70 00 ext. 7671
More information about the Freeradius-Users