Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support Administration of the Avaya G350 Media Gateway - Avaya Support

downloads.avaya.com
from downloads.avaya.com More from this publisher
13.07.2015 Views

FIPSTable 15: Critical security parameters 2 of 3Key Description/Usage StorageIKE Session Phase 1 DES keyIKE Session Phase 1 AES keyNoncie, NoncerIPSEC SA phase-2 TDES keyIPSEC SA phase-2 DES keyIPSEC SA phase-2 AES keyIPSEC SA phase-2, HMACkeysIPSEC SA phase-2 keys perprotocolDH private key phase-2DH shared secret phase-2IPSEC SA phase-2 keys perprotocolUser passwordRoot passwordRadius SecretPPPoE CHAP/PAP SecretOSPF SecretSNMPv3 user authenticationpasswordKey used for DES data encryption ofISAKMP SAKey used for AES data encryption ofISAKMP SAPhase 2 initiator and responder noncePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2 Diffie Hellman private keysused in PFS for key renewalPhase 2PFS Diffie Hellman sharedsecret used in PFS for key renewalPhase 2, basic quick modeUsed for password authentication of CLIusersUsed for authentication of default CLIuser during first setupUsed for hashing password with MD5.One secret common to both Primary andSecondary Radius server.Used for authentication to PPPoE serverUsed for hashing password with MD5.One secret defined per peer routeridentity.SNMPv3 operator MD5 authenticationpassword used for authenticating toUser and Read-Only User rolesX9.31 PRNG key Key for X9.31 PRNG2 of 3298 Administration of the Avaya G350 Media Gateway

OverviewTable 15: Critical security parameters 3 of 3Key Description/Usage StorageFixed Serial Number secretEphemeral Serial NumbersecretThe TDES key used for the firstexchange of the serial number and newsession key between Gateway andS8300/Blade server entityThe TDES key used for serial numberand key renewal. This key is periodicallyre-negotiated between S8300/Bladeserver entity and the Gateway.3 of 3Public keysTable 16 lists the public keys available in the module:Table 16: Public keysKeyEphemeral DH phase-1 publickeysEphemeral DH phase-2 publickeysImage download certificate(Avaya root CA RSA public key)License download public keyDescription/UsageGenerated for VPN IKE Phase 1 keyestablishmentGenerated for VPN IKE Phase 2 PFS keyrenewalUsed for authentication of software download.The Avaya Root certificate is hard-coded in theGateway image and is used directly forauthentication of the chain of trust of the AvayaSigning Authority that is downloaded togetherwith the software.Used for authentication of license file validity. Thelicense signing authority public key is hard-codedin the Gateway image and is used directly forauthentication of the digital signature embeddedin the license file.Issue 3 January 2005 299

FIPSTable 15: Critical security parameters 2 <strong>of</strong> 3Key Description/Usage StorageIKE Session Phase 1 DES keyIKE Session Phase 1 AES keyNoncie, NoncerIPSEC SA phase-2 TDES keyIPSEC SA phase-2 DES keyIPSEC SA phase-2 AES keyIPSEC SA phase-2, HMACkeysIPSEC SA phase-2 keys perprotocolDH private key phase-2DH shared secret phase-2IPSEC SA phase-2 keys perprotocolUser passwordRoot passwordRadius SecretPPPoE CHAP/PAP SecretOSPF SecretSNMPv3 user au<strong>the</strong>nticationpasswordKey used for DES data encryption <strong>of</strong>ISAKMP SAKey used for AES data encryption <strong>of</strong>ISAKMP SAPhase 2 initiator and responder noncePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2, basic quick modePhase 2 Diffie Hellman private keysused in PFS for key renewalPhase 2PFS Diffie Hellman sharedsecret used in PFS for key renewalPhase 2, basic quick modeUsed for password au<strong>the</strong>ntication <strong>of</strong> CLIusersUsed for au<strong>the</strong>ntication <strong>of</strong> default CLIuser during first setupUsed for hashing password with MD5.One secret common to both Primary andSecondary Radius server.Used for au<strong>the</strong>ntication to PPPoE serverUsed for hashing password with MD5.One secret defined per peer routeridentity.SNMPv3 operator MD5 au<strong>the</strong>nticationpassword used for au<strong>the</strong>nticating toUser and Read-Only User rolesX9.31 PRNG key Key for X9.31 PRNG2 <strong>of</strong> 3298 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!