ip touch 4038 - problem with certificate download

marc_bo
Member
Posts: 5
Joined: 31 Oct 2014 05:36
Location: Germany - Freiburg

ip touch 4038 - problem with certificate download

Post by marc_bo »

Hello,

I'm new at the forum and from Germany so please excuse my bad english.

I have to set up network access control in our company. And my Problem is to get the certificates automaticly to the IP touch 4038.

I set up the lanpbx.cfg like this:
CERTSRV_IP=10.15.3.20 CERTSRV_PORT=80 CERTSRV_PATH=/certserv

The certificate is at the folder /certserv like this: "macaddress-ip-phone".pfx

When the IPphone boots up, I have the following steps:
1/5network start
2/5 network setup
3/5 config download
bad file content
5/5 connecting
connected


Hope anybody can help me!!

kind regards
Marc
User avatar
frank
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 3169
Joined: 06 Jul 2004 00:18
Location: New York
Contact:

Re: ip touch 4038 - problem with certificate download

Post by frank »

So your lanpbx.cfg looks kind of like this:

Code: Select all

TYPE=A4400 VERSION=1 IP_DOWNLOAD=192.168.1.120 IP_CPU1=192.168.1.120
CERTSRV_IP=1.2.3.4 CERTSRV_PORT=80 CERTSRV_PATH=/certsrv
?
Code Free Or Die
marc_bo
Member
Posts: 5
Joined: 31 Oct 2014 05:36
Location: Germany - Freiburg

Re: ip touch 4038 - problem with certificate download

Post by marc_bo »

Hello,

my lanpbx.cfg first looks like this:

Code: Select all

CERTSRV_IP=10.1.3.2 CERTSRV_PORT=80 CERTSRV_PATH=/certserv
Now I fixed like this:

Code: Select all

TYPE=A4400 VERSION=1 IP_DOWNLOAD=10.1.2.3 IP_CPU1=10.1.2.4 IP_CPU2=10.1.2.5
CERTSRV_IP=10.1.3.2 CERTSRV_PORT=80 CERTSRV_PATH=/certserv
Now I can see no bad file error. But my certificate will not be downloaded automaticly.
User avatar
tot3nkopf
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 4058
Joined: 02 Feb 2006 10:41
Location: Germany & Romania
Contact:

Re: ip touch 4038 - problem with certificate download

Post by tot3nkopf »

Which is the type of access required by the web server? (anonymous or basic?)
Did you configured the access user and password on IP Touch? (default user is ALCIPT and no password is configured by default)
marc_bo
Member
Posts: 5
Joined: 31 Oct 2014 05:36
Location: Germany - Freiburg

Re: ip touch 4038 - problem with certificate download

Post by marc_bo »

In my test I use Apache (XAMPP) and in the conf is the basic access loaded:
LoadModule auth_basic_module modules/mod_auth_basic.so
#LoadModule authn_anon_module modules/mod_authn_anon.so

Should I try with anonymous?

There are no credentials configured, I use the standard user ALCIPT without a password.



Additional Information:
I tried with a certificate with password and one without.

I can download the certificate manually on the IP touch Phone "Menu\Certificate\Get Certificate".
When i go to the get certificate menu i see my IP parameters, which I set in my lanpbx.cfg...
User avatar
frank
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 3169
Joined: 06 Jul 2004 00:18
Location: New York
Contact:

Re: ip touch 4038 - problem with certificate download

Post by frank »

I would say try with anonymous
Code Free Or Die
marc_bo
Member
Posts: 5
Joined: 31 Oct 2014 05:36
Location: Germany - Freiburg

Re: ip touch 4038 - problem with certificate download

Post by marc_bo »

I tried but no changes...

The thing is, when i start the download manually it works!
User avatar
cavagnaro
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 7014
Joined: 14 Sep 2005 19:45
Location: Brasil, Porto Alegre
Contact:

Re: ip touch 4038 - problem with certificate download

Post by cavagnaro »

Then probably the certificate format is not correct?
Ignorance is not the problem, the problem is the one who doesn't want to learn

OTUC/ICS ACFE/ACSE R3.0/4.0/5.0/6.0
Certified Genesys CIV 8.5
Certified Genesys Troubleshooting 8.5
Certified Genesys BEP 8.x
Genesys Developer
User avatar
tot3nkopf
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 4058
Joined: 02 Feb 2006 10:41
Location: Germany & Romania
Contact:

Re: ip touch 4038 - problem with certificate download

Post by tot3nkopf »

marc_bo wrote:I tried but no changes...

The thing is, when i start the download manually it works!
You need to activate manually the certificate... (at least in my understanding from what I have read in the docs) I do not think this can work automatically...Raise an eSR and ask ALU if this is the case and maybe open a feature req for an automated process...
Funny is that we need to do the same tests here.. :) I will come back.
User avatar
tot3nkopf
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 4058
Joined: 02 Feb 2006 10:41
Location: Germany & Romania
Contact:

Re: ip touch 4038 - problem with certificate download

Post by tot3nkopf »

cavagnaro wrote:Then probably the certificate format is not correct?
Manually it is working....
Post Reply

Return to “Security and Access Control”