19.07.2013 Views

Cisco Unified Contact Center Enterprise Solution Reference ...

Cisco Unified Contact Center Enterprise Solution Reference ...

Cisco Unified Contact Center Enterprise Solution Reference ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7 Securing <strong>Unified</strong> CCE<br />

OL-8669-05<br />

<strong>Cisco</strong> <strong>Unified</strong> <strong>Contact</strong> <strong>Center</strong> <strong>Enterprise</strong> 7.x SRND<br />

Endpoint Security<br />

Figure 7-5 shows the Certificate Authority enrollment procedure to generate certificates used by the<br />

agent and the servers. The agent desktop certificate enrollment process is manual, requiring the creation<br />

of certificate signing requests (CSRs) at each endpoint, which are then transferred to the certificate<br />

authority responsible for signing and generating the certificates.<br />

Figure 7-5 Certificate Authority Enrollment Procedure<br />

Generate key's<br />

Private Public<br />

User key's<br />

End Host<br />

Certificate<br />

request<br />

<strong>Unified</strong> IP Phone Device Authentication<br />

When designing a <strong>Unified</strong> CCE solution based on <strong>Cisco</strong> <strong>Unified</strong> CallManager Release 4.x or 5.0,<br />

customers may choose to implement device authentication for the <strong>Cisco</strong> <strong>Unified</strong> IP Phones 7940, 7960,<br />

or 7970. <strong>Unified</strong> CCE 7.0 was tested with <strong>Cisco</strong> <strong>Unified</strong> CallManager's Authenticated Device Security<br />

Mode, which ensures the following:<br />

Device Identity — Mutual authentication using RSA signatures<br />

Signaling Integrity — SCCP messages authenticated using HMAC-SHA-1<br />

Signaling Privacy — SCCP message contents encrypted using AES-128-CBC<br />

<strong>Unified</strong> IP Phone Media Encryption<br />

Step 1 Step 2<br />

Step 3<br />

Step 4<br />

Step 5<br />

CA's keys<br />

Private Public<br />

Certificate Authority<br />

Media encryption is not supported in a <strong>Unified</strong> CCE environment. Silent monitoring or call recording<br />

functionality is not available on <strong>Unified</strong> IP phones where the media is encrypted using Secure Real-Time<br />

Transport Protocol (SRTP).<br />

Sign<br />

End host<br />

certificate<br />

143958<br />

7-21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!