Security Management Fundamentals Release: 6.0 Document Revision: 03.08
Total Page:16
File Type:pdf, Size:1020Kb
Nortel Communication Server 1000 Security Management Fundamentals Release: 6.0 Document Revision: 03.08 www.nortel.com .NN43001-604 Nortel Communication Server 1000 Release: 6.0 Publication: NN43001-604 Document release date: 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. While the information in this document is believed to be accurate and reliable, except as otherwise expressly agreed to in writing NORTEL PROVIDES THIS DOCUMENT "AS IS" WITHOUT WARRANTY OR CONDITION OF ANY KIND, EITHER EXPRESS OR IMPLIED. The information and/or products described in this document are subject to change without notice. Nortel, Nortel Networks, the Nortel logo, and the Globemark are trademarks of Nortel Networks. All other trademarks are the property of their respective owners. 3 . Contents New in this release 11 Other changes 11 Revision history 11 How to get help 15 Getting help from the Nortel Web site 15 Getting help over the telephone from a Nortel Solutions Center 15 Getting help from a specialist by using an Express Routing Code 16 Getting help through a Nortel distributor or reseller 16 Introduction 17 Purpose 17 Navigation 18 Other security information 18 About this document 19 Subject 19 Intended audience 20 Terminology conventions 20 Fundamentals of system security management 21 System security overview 23 General signaling security overview 23 Key management concepts 23 Public-key certificate concepts 25 Platform security overview 28 Unified Communications Management security services 28 Unified Communications Management security server roles 29 Security Domain Manager concepts 30 Linux security hardening 31 Internal communications security overview 36 ISSS/IPsec 36 Secure File Transfer Protocol concepts 38 Port access restrictions concepts 40 Linux Master Firewall Control 41 Media and signaling security overview 42 Nortel Communication Server 1000 Security Management Fundamentals NN43001-604 03.08 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. 4 Media Security concepts 42 TLS security for SIP trunks concepts 44 UNIStim signaling encryption with DTLS 44 NRS SIP Proxy 44 User and password management concepts 45 OAM overview 45 Access control management 47 System upgrade password conversion 48 Global password settings 48 Role management in Unified Communications Management 49 Security administration concepts 49 SSH and secure remote access 49 Customizable logon banner 49 Recommended security practices 51 Recommendations for OAM security 51 Recommended password management practices 52 Upgrading user names from an earlier release 52 Recommendations to protect confidentiality 53 ISSS/IPsec recommendations 53 Preshared keys, SSH keys, and Secure FTP Token recommendations 53 TLS security for SIP trunks recommendations 54 Media Security recommendations 54 Recommendations for security administration 54 Shell Access Control 54 Certificates 55 Security code for Mobile Extensions 55 Single sign-on cookie domain 55 Certificate management 56 Upgrade from an earlier release 56 Recommendations to protect UNIStim IP Phones 57 UNIStim with DTLS recommendations 57 Prevent GARP spoof attacks 57 Enable layer 2 authentication for IP Phones 58 Sign files 58 Security interactions 58 Co-resident CP PM Call and Signaling Server 59 ISSS and Element Manager on VxWorks signaling server 59 ISSS and Element Manager on UCM 60 ISSS and Geographic Redundancy 60 ISSS and AML 61 ISSS and Port Access Restrictions and Linux firewall 61 ISSS and other protocols 62 Media Security and call forwarding 62 Nortel Communication Server 1000 Security Management Fundamentals NN43001-604 03.08 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. 5 Media Security and SIP phones 62 Media Security Always and CallPilot mailboxes on systems without MGC daughterboards or MC32S 63 SIP TLS security policy interaction with Failsafe NRS 63 SIP TLS interaction with SMC 2450 64 Recommendations for upgrading to Communication Server 1000 Release 6.0 from a previous release 64 Prerequisites 64 Migrate existing CS 1000 Release 5.x user accounts to CS 1000 Release 6.0 66 Prerequisites 66 ISSS 69 ISSS overview 69 Unified Communications Management IPsec ISSS management interface page 71 IPsec configuration 74 Prerequisites 74 Configure ISSS for a new installation 74 Configure default IPsec settings 76 Add a new manual IPsec target 78 Edit an existing manual IPsec target 79 Enable or disable IPsec for a target 80 Delete a manual target 81 Customize IPsec for a Call Server target 82 Activate IPsec configuration settings 84 Synchronize IPsec configuration settings 85 Configure ISSS when a new element joins the security domain 86 Other ISSS configuration and maintenance procedures 87 Maintenance on Linux servers 87 Manual ISSS configuration on each device 90 Certificate Management 95 Prepare the system for certificate management 95 CA management 96 Private CA Configuration 96 Add a CA to an endpoint 99 Change the trust status of an endpoint 101 Delete a CA 102 Certificate creation and management 103 Certificate information 105 Add a UCM server certificate to the Web browser 106 Create a certificate for Web SSL signed by the private CA 107 Create a certificate for Web SSL signed by a trusted third-party CA 112 Create a self-signed certificate for Web SSL 117 Create a certificate for SIP TLS signed by the private CA 123 Nortel Communication Server 1000 Security Management Fundamentals NN43001-604 03.08 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. 6 Create a certificate for SIP TLS signed by a public CA 128 Create a request for a third-party CA certificate for SIP TLS when upgrading the system 133 Create a self-signed certificate for SIP TLS 140 Process a pending certificate response 144 Delete a pending certificate request 146 Create a certificate renew request for the current certificate 148 Export the current self-signed certificate 151 Export the current certificate and its private key 153 Import a certificate and its private key from a file 156 Assign an existing certificate 159 Replace the current certificate 161 Remove the current certificate 163 Revoke a certificate 165 Download the Certificate Revocation List (CRL) Details 166 SIP security 169 About TLS security for SIP trunks 169 SIP Lines 171 SIP TLS configuration overview 171 View SIP TLS configuration 174 Job aid: config.ini 174 TLS security for SIP trunks configuration using Element Manager 175 Configuring SIP TLS security policy 176 SIP TLS Certificate management 181 SIP TLS maintenance using CLI 181 Media Security 183 About Media Security 183 UNIStim with DTLS encryption 185 DTLS and IP Phone registration 186 Security levels 187 DTLS configuration options 188 UNIStim DTLS overlay commands 189 Configure UNIStim DTLS using Element Manager 190 Update UNIStim DTLS using Element Manager 193 View UNISTIM DTLS details using Element Manager 194 Key sharing 196 Protecting the media stream using SRTP PSK 196 Protecting the media stream using SRTP USK 196 Media Security configuration using Element Manager 196 System-wide Media Security configuration 196 VTRK Class of Service configuration 199 Media Security configuration using overlays 201 System-wide Media Security configuration 201 Nortel Communication Server 1000 Security Management Fundamentals NN43001-604 03.08 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. 7 Class of Service configuration 202 VTRK Class of Service configuration 204 Media Security configuration information 205 Media Security configuration information available using overlays 205 Media Security information available using an IP Phone 207 SIP Route information available using overlays 208 User and password management 209 Roles and permissions 210 Inheritance of UCM role-based permissions for Element type of CS 1000 211 Permission templates 211 Account types and roles 212 Account synchronization 212 Customer passwords 212 User and password management using overlays 214 User management 214 Password management 224 Global password settings configuration 226 Password reset 228 Multi-user login configuration using overlays 231 History File configuration using overlays 233 Password management for stand-alone Signaling Server 233 User and password management using Element Manager 234 Add a user 234 Edit an existing user 239 Synchronize a changed password 241 Edit global password settings 242 Security administration 247 Control access to the system 247 System administration port security 248 Switchroom security 248 Network facilities security 249 Add or remove elements from the UCM security domain 249 VxWorks systems and devices 251 Co-resident Call Server and Signaling Server systems 252 Join a Co-resident Signaling Server to the UCM security domain using Base Manager 253 Redundant systems 266 Move an element from one UCM security domain to another 267 Moving a Linux member element to another UCM security domain 267 Moving a single VxWorks element to another UCM security domain 268 Moving all VxWorks elements on a Call Server to another UCM security domain 269 Authentication methods 269 Nortel Communication Server 1000 Security Management Fundamentals NN43001-604 03.08 14 April 2010 Copyright © 2008-2010 Nortel Networks. All Rights Reserved. 8 Central authentication 270 Secure UserID and password authentication with a system security token 271 Regenerate the Secure FTP Token 272 Refresh system keys 272 Control access to system Application Processors 273 Configure Secure File Transfer Protocol 274 sFTP configuration