| |
| News & Reviews |
Welcome to the Voxilla VoIP Forum.
Voxilla has been a trusted source for accurate, up-to-date information on the IP Communications industry since 2002. A dedicated staff of reporters and engineers produce feature articles and product reviews to keep industry watchers abreast of the people, companies, and trends driving a fast moving market.
You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!
If you have any problems with the registration process or your account login, please contact contact us.
Voxilla VoIP Forum |
SIP over TLSA forum dedicated to VoIP Security issues, trends, technical support, how-to guides, troubleshooting, and general assistance. |
| | LinkBack | Thread Tools | Rate Thread | Display Modes |
| |||
| I have two Linksys SPA-3102 both with certificates generated by Voxilla, my question is: how can I make them work together (direct connection) using TLS as transport for SIP? I've activated this option on both but nothing happens if I don't select UDP as transport. Everything works fine if using UDP though... SRTP also works fine between the two. Do I need to use a provider that supports TLS for them to work? I would rather have direct connections. I would really appreciate if anyone can help me with this. |
| |||
| For TLS certificate-based authentication to work, one end has to be a server and the other end has to be a client. (See TLS handshake protocol). The Linksys adapter can work as a TLS client, but not as a server. Consequently, when you enable TLS on both adapters, both are ready to act as TLS clients, but none as a TLS server. With UDP, we don't have this issue. UDP can be used for SIP to create direct peer-to-peer session. One of the possible solutions is to use an IP-PBX to act as TLS server. Both adapters will setup TLS with the IP-PBX. Of course, if these two adapters are geographically not co-located, then you will need static IP for the IP-PBX. OpenSER is a good example of free IP-PBX with TLS support. |
| |||
| If you want to get TLS working you need a server that does TLS. If you want to try open source, check out the latest SER. It comes with a proper TLS support. If you use this one, you will have to negotiate the SRTP keys "through" the proxy - which should be no problem. If you want to use a PBX, open source seems not to be an option at the moment. So far it seems that only pbxnsip offers TLS support. It works with counterpath, InGate, Polycom and snom and also some others and it uses the SDES key exchange which seems to be the way to go. Not sure if it works with the Linksys TLS, but it is worth a try. |
| Thread Tools | |
| Display Modes | Rate This Thread |
| |
| | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| VOIP Provider using TLS/SSL | sysknil | VoIP Security | 3 | May 3rd, 2007 09:46 PM |
| Help: Configuring SPA3102 with TLS SIP Transport | sysknil | Linksys (Sipura) VoIP Support Forum | 0 | March 30th, 2007 12:27 AM |
| What VoIP Providers support SIPS (SIP over TLS) | jasonwc | Other Providers | 0 | December 19th, 2006 10:33 PM |
| Linksys SIP TLS works with CommuniGate Pro | eric | CommuniGate Pro Support Forum | 2 | December 11th, 2006 06:02 PM |
| SPA3102 Sip Transport:UDP/TCP/TLS | coombabah | Linksys (Sipura) VoIP Support Forum | 2 | December 9th, 2006 11:43 PM |