Secure Authentication from WAN

Get help with installing, upgrading and running Asterisk.

Moderators: muppetmaster, Moderator, Support

Secure Authentication from WAN

Postby gatorback » Sun Aug 05, 2012 10:22 am

I have stood up Asterisk and would like to be able to use my travel ATA (SPA1001) to securely authenticate to the asterisk server from the internet (non LAN side).

There is a SPA 1001 has Subscriber information fields:

1) Mini certificate
2) SRTP Private Key

Image

I would like to be able to send the username \ pw securely to the Asterisk server. Are there any examples of configuring Asterisk to do this? My Google search was not successful. If you have experience successfully doing this, please indicate this in the response.

Constructive and actionable responses are highly appreciated. Thank you.
Free Asterisk Book| Asterisk 1.8.18 on Optware ASUS RT-N16 | Linksys SPA2102 | G729a codec bandwidth
gatorback
Oldsterisk
 
Posts: 79
Joined: Fri May 20, 2011 1:48 pm

Re: Secure Authentication from WAN

Postby malcolmd » Mon Aug 06, 2012 7:31 am

If you want to secure your signaling to Asterisk, you'll use TLS. I've no idea if that device supports TLS transport for SIP signaling.
Malcolm Davenport
Digium, Inc. | Senior Product Manager
malcolmd
Moves Like Spencer
 
Posts: 2200
Joined: Wed Aug 03, 2005 3:53 pm
Location: Huntsville, AL, US

Re: Secure Authentication from WAN

Postby gatorback » Tue Aug 07, 2012 10:30 am

Thank Malcolm. My SPA3102 device supports TLS SIP Transport:

Image

Does this encrypt the credentials or the voice data?

Thank you.
Free Asterisk Book| Asterisk 1.8.18 on Optware ASUS RT-N16 | Linksys SPA2102 | G729a codec bandwidth
gatorback
Oldsterisk
 
Posts: 79
Joined: Fri May 20, 2011 1:48 pm

Re: Secure Authentication from WAN

Postby david55 » Tue Aug 07, 2012 11:09 am

TLS encrypts the signalling path, which includes the credentials. SRTP encrypts the speech.
david55
Moves Like Spencer
 
Posts: 7723
Joined: Fri Sep 26, 2008 5:03 am

Re: Secure Authentication from WAN

Postby gatorback » Tue Aug 07, 2012 1:03 pm

Thanks David55. It would seem that unless you change the above setting to TLS with your VOIP provider, then one is sending their username and password unencrypted? I'm hoping that I'm wrong about this, but I hope someone that is using encryption with one of these SPA-ish device will comment.
Free Asterisk Book| Asterisk 1.8.18 on Optware ASUS RT-N16 | Linksys SPA2102 | G729a codec bandwidth
gatorback
Oldsterisk
 
Posts: 79
Joined: Fri May 20, 2011 1:48 pm

Re: Secure Authentication from WAN

Postby david55 » Tue Aug 07, 2012 3:04 pm

If they offer MD5 authentication, the password will be hashed with a varying nonce. Asterisk does this.
david55
Moves Like Spencer
 
Posts: 7723
Joined: Fri Sep 26, 2008 5:03 am


Return to Asterisk Support

Who is online

Users browsing this forum: No registered users and 29 guests