Switch from Thales encryption to native encryption
Posted: 09 Mar 2024 06:41
Hello,
I have a somewhat complex environment: two active OXE nodes and another two standby ones using Thales encryption. I need to join all the phones (6.000) in just one new virtual OXE (one active node and another standby one), preferibly using native encryption.
Thales ciphers are set up between phone terminals and the OXEs:
Now
Phone terminals -> Thales cipher 1 -> OXE1
Phone terminals -> Thales cipher 2 -> OXE2
Desired change
Phone terminals -> virtual OXE (with native encryption)
Also possible
Phone terminals -> Thales cipher 1 -> virtual OXE
The problem I am facing with is about clearing the encryption in the phone terminals (IP Touch 40xx and IP Touch 80xx) as it seems that they kept some key from Thales ciphers and they do not register on the new virtual OXE node without manual user action whenever I activate the cipher again.
I have tried to remove the Thales ciphers so that traffic do not goes through them. Everything works fine, but on putting againg the Thales cipher 1 in front of the OXE, the terminals which used the Thales cipher 2 seem to refuse to accept the encryption keys from that cipher unit.
I would rather enable native encryption, but then again, I do not know how to clear automatically the encryption keys in the phone terminals so that they register with the new virtual OXE as the would do the first time.
Is there any way to clear up the encryption of the Thales boxes. I read in a previous post that:
"You switch your installation to not encrypted, reboot the CPUS, all the phones are going to reboot and be OK. This is done by renaming the labpbx file from encrypted to not encrypted extension."
How can I remane the labpbx file in six thousand phones automatically?
Do you know whether there is any way to acomplish what I need to do?
Regards,
I have a somewhat complex environment: two active OXE nodes and another two standby ones using Thales encryption. I need to join all the phones (6.000) in just one new virtual OXE (one active node and another standby one), preferibly using native encryption.
Thales ciphers are set up between phone terminals and the OXEs:
Now
Phone terminals -> Thales cipher 1 -> OXE1
Phone terminals -> Thales cipher 2 -> OXE2
Desired change
Phone terminals -> virtual OXE (with native encryption)
Also possible
Phone terminals -> Thales cipher 1 -> virtual OXE
The problem I am facing with is about clearing the encryption in the phone terminals (IP Touch 40xx and IP Touch 80xx) as it seems that they kept some key from Thales ciphers and they do not register on the new virtual OXE node without manual user action whenever I activate the cipher again.
I have tried to remove the Thales ciphers so that traffic do not goes through them. Everything works fine, but on putting againg the Thales cipher 1 in front of the OXE, the terminals which used the Thales cipher 2 seem to refuse to accept the encryption keys from that cipher unit.
I would rather enable native encryption, but then again, I do not know how to clear automatically the encryption keys in the phone terminals so that they register with the new virtual OXE as the would do the first time.
Is there any way to clear up the encryption of the Thales boxes. I read in a previous post that:
"You switch your installation to not encrypted, reboot the CPUS, all the phones are going to reboot and be OK. This is done by renaming the labpbx file from encrypted to not encrypted extension."
How can I remane the labpbx file in six thousand phones automatically?
Do you know whether there is any way to acomplish what I need to do?
Regards,