NATIVE ENCRYPTION PARAMETERS

System_Option
Enable Native Encryption

This parameter controls if the system should support native encryption (DTLS) or not

YES: Native Encryption is enabled on the system. i.e. DTLS is supported.

It allows endpoints to connect in cipher mode.

NO(default):DTLS is not supported.

Native Encryption is disabled on the system. i.e. DTLS is not supported.

Endpoints connect in clear mode.

Note:

(1) Modification of this parameter requires to build a new lanpbx.cfg file and reboot of OXE.



Enable Automatic CTL Acquisition

This parameter controls if the Certification Trust List (CTL) is to be automatically transferred from the OXE to the endpoints.

Yes: CTL list is transferred to the end points automatically via lanpbx.cfg file.

No: CTL list not added to the lanpbx.cfg file. In this case, CTL must be downloaded into the end points manually.

Note:

(1) This option is applicable only if the parameter Enable Native Encryption is set to yes.

(2) Modification of this parameter requires to build a new lanpbx.cfg file and reboot of OXE.



Enable Mutual TLS Authentication

This parameter controls if CS should Authenticate endpoints (clients) or not.

Yes: CS authenticates endpoints via client certification during DTLS session establishment.

No: CS does not authenticate endpoints.

Note:

(1)This option is applicable only if the parameter Enable Native Encryption is set to yes.

(2)Modification of this parameter requires to build a new lanpbx.cfg file and reboot of OXE.



Set_ECDHE_RSA_AES256_GCM_SHA384

Please select supported cipher suites from the list.

Yes: The respective Cipher Suite is Supported

No: The respective Cipher Suite is not Supported



Set_ECDHE_RSA_AES128_GCM_SHA256

Please select supported cipher suites from the list.

Yes: The respective Cipher Suite is Supported

No: The respective Cipher Suite is not Supported



Authentication for SRTP

Authenticated SRTP

SRTP authentication:

- no authentication

- authentication tag sending without received tag check

- authentication tag sending and received tag check

For SRTP authentication (1),(2) system option 'Enable Native Encryption' must be set to True