[YMCS/YDMP Free Trial Program]Yealink would like to offer Free Trial Program of Yealink device management service for our current eligible customers. You can see the details below.
https://www.yealink.com/ydmp-freetrial-2020


Post Reply 
 
Thread Rating:
  • 1 Votes - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
T46S SSL
Author Message
Mycal Offline
Junior Member
**

Posts: 6
Joined: Nov 2017
Reputation: 0
Post: #1
T46S SSL
Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,
(This post was last modified: 11-15-2017 10:32 PM by Mycal.)
11-15-2017 06:16 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Kevin_Yealink Offline
Administrator
*******

Posts: 204
Joined: Jul 2016
Reputation: 2
Post: #2
RE: T46S SSL
(11-15-2017 06:16 PM)Mycal Wrote:  Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,

Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin
11-16-2017 06:56 AM
Find all posts by this user    like1    dislike0 Quote this message in a reply
Mycal Offline
Junior Member
**

Posts: 6
Joined: Nov 2017
Reputation: 0
Post: #3
RE: T46S SSL
We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?



(11-16-2017 06:56 AM)Kevin_Yealink Wrote:  
(11-15-2017 06:16 PM)Mycal Wrote:  Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,

Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin
11-28-2017 06:58 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Kevin_Yealink Offline
Administrator
*******

Posts: 204
Joined: Jul 2016
Reputation: 2
Post: #4
RE: T46S SSL
(11-28-2017 06:58 PM)Mycal Wrote:  We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?



(11-16-2017 06:56 AM)Kevin_Yealink Wrote:  
(11-15-2017 06:16 PM)Mycal Wrote:  Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,

Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin

Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Attached File(s)
.docx  how to autop.docx (Size: 135.59 KB / Downloads: 11)
11-29-2017 07:10 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Mycal Offline
Junior Member
**

Posts: 6
Joined: Nov 2017
Reputation: 0
Post: #5
RE: T46S SSL
(11-29-2017 07:10 AM)Kevin_Yealink Wrote:  
(11-28-2017 06:58 PM)Mycal Wrote:  We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?



(11-16-2017 06:56 AM)Kevin_Yealink Wrote:  
(11-15-2017 06:16 PM)Mycal Wrote:  Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,

Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin

Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,
11-29-2017 05:28 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Kevin_Yealink Offline
Administrator
*******

Posts: 204
Joined: Jul 2016
Reputation: 2
Post: #6
RE: T46S SSL
(11-29-2017 05:28 PM)Mycal Wrote:  
(11-29-2017 07:10 AM)Kevin_Yealink Wrote:  
(11-28-2017 06:58 PM)Mycal Wrote:  We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?



(11-16-2017 06:56 AM)Kevin_Yealink Wrote:  
(11-15-2017 06:16 PM)Mycal Wrote:  Hey all,

Does anyone happen to know if there is a setting or firmware update that disables SSL v2 v3 and DES and IDEA ciphers for this model phone? They are showing up on vulnerability scans.

Thank you,

Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin

Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,
11-29-2017 05:35 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Kevin_Yealink Offline
Administrator
*******

Posts: 204
Joined: Jul 2016
Reputation: 2
Post: #7
RE: T46S SSL
(11-29-2017 05:35 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:28 PM)Mycal Wrote:  
(11-29-2017 07:10 AM)Kevin_Yealink Wrote:  
(11-28-2017 06:58 PM)Mycal Wrote:  We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?



(11-16-2017 06:56 AM)Kevin_Yealink Wrote:  Hi

We support to disable it. Please kindly Auto provision the phone with below parameter:
sip.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL
security.tls_cipher_list = AES:!ADH:!LOW:!EXPORT:!NULL

Let me know if any update.

BR
Kevin

Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,

Hi

Not, it will only configure this parameter, it will not clear other configuration.

Best Regards,
Kevin
11-29-2017 05:36 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Mycal Offline
Junior Member
**

Posts: 6
Joined: Nov 2017
Reputation: 0
Post: #8
RE: T46S SSL
(11-29-2017 05:36 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:35 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:28 PM)Mycal Wrote:  
(11-29-2017 07:10 AM)Kevin_Yealink Wrote:  
(11-28-2017 06:58 PM)Mycal Wrote:  We cannot due to the structure and architecture of our network auto provision the phones. Is there any way to make this change other than auto provisioning?

Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,

Hi

Not, it will only configure this parameter, it will not clear other configuration.

Best Regards,
Kevin


Hey Kevin,

Could you send me some documentation on how to generate the config file and what I would need to do to set up the auto provision server and how to point the phones at it?

Thank you,
11-29-2017 05:43 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Kevin_Yealink Offline
Administrator
*******

Posts: 204
Joined: Jul 2016
Reputation: 2
Post: #9
RE: T46S SSL
(11-29-2017 05:43 PM)Mycal Wrote:  
(11-29-2017 05:36 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:35 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:28 PM)Mycal Wrote:  
(11-29-2017 07:10 AM)Kevin_Yealink Wrote:  Hi

This method only can configure via AutoP. AutoP is easy for you and you just need to set up a small HTTP server in your personal computer.
I attached provision cfg file and guide for how to provision with HFS tool.
Please kindly test in your side.


Best Regards
Kevin


Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,

Hi

Not, it will only configure this parameter, it will not clear other configuration.

Best Regards,
Kevin


Hey Kevin,

Could you send me some documentation on how to generate the config file and what I would need to do to set up the auto provision server and how to point the phones at it?

Thank you,

Hi

You can get all file from this link:
https://ftp.yealink.com/?ShareToken=24C2...8E66E5918E

Best Regards,
Kevin
11-29-2017 05:58 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Mycal Offline
Junior Member
**

Posts: 6
Joined: Nov 2017
Reputation: 0
Post: #10
RE: T46S SSL
(11-29-2017 05:58 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:43 PM)Mycal Wrote:  
(11-29-2017 05:36 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:35 PM)Kevin_Yealink Wrote:  
(11-29-2017 05:28 PM)Mycal Wrote:  Hey Kevin,

As I previously stated auto provisioning will not work given our architecture we do not have these phones on a local subnet and in certain cases we do not have access to the phones at all. Is there a way to manually import said config file? Will this config file remove the manually configured settings on the phones? If so will we need to generate a config file for each phone specifically?

Thank you,

Hi

Not, it will only configure this parameter, it will not clear other configuration.

Best Regards,
Kevin


Hey Kevin,

Could you send me some documentation on how to generate the config file and what I would need to do to set up the auto provision server and how to point the phones at it?

Thank you,

Hi

You can get all file from this link:
https://ftp.yealink.com/?ShareToken=24C2...8E66E5918E

Best Regards,
Kevin


Thank you very much Kevin! One last thing they came up showing support for the DES and IDEA ciphers could you give me the lines I would need to add to disable that was well?

Thank you,
(This post was last modified: 11-30-2017 02:15 PM by Mycal.)
11-30-2017 02:15 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Ringer Loud on Yealink T46S when using WH62 Dual Headset KellyL@AlternateAccess.com 0 292 07-07-2022 05:06 AM
Last Post: KellyL@AlternateAccess.com
  T46S AntalVincz69 3 851 07-01-2022 01:38 AM
Last Post: complex1
  T42S & T46S On Vonage stratos 1 610 06-16-2022 05:31 PM
Last Post: complex1
  T46S change device certificate Fritz-EDV 1 773 05-11-2022 06:20 PM
Last Post: Fritz-EDV
Sad T46S: small and severe audio interruptions ronald.swaypc 0 691 04-05-2022 08:57 PM
Last Post: ronald.swaypc
  Factory reset T46s w/o admin password DanielP 7 10,570 12-02-2021 06:07 PM
Last Post: complex1
  T46S won't register yealink@vespino.nl 2 3,187 11-11-2021 10:38 PM
Last Post: yealink@vespino.nl
  Unknown Icon in T46S kadinter 0 1,867 10-26-2021 08:47 PM
Last Post: kadinter
  Screensaver Wait time on T46S remi-it 3 3,135 10-21-2021 01:49 AM
Last Post: complex1
  T46S-Vonage Overwriting Remote Directory igendreau 1 2,259 09-29-2021 03:30 AM
Last Post: complex1

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Contact Us   Yealink   Return to Top   Return to Content   Lite (Archive) Mode   RSS Syndication