[YMCS/YDMP Free Trial Program]Yealink would like to offer Free Trial Program of Yealink device management service for our current eligible customers. You can see the details below.
https://www.yealink.com/ydmp-freetrial-2020


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
T46g & T48G RADIUS 802.1x and SHA256
Author Message
Bigmac Offline
Junior Member
**

Posts: 8
Joined: Mar 2016
Reputation: 0
Post: #1
Bug T46g & T48G RADIUS 802.1x and SHA256
Hi Guys,

In the past, the RADIUS Authentication 802.1x worked beautifully with the Yealink T46g & T48G Phones.

Now we create a new CA Root Certificate.
The old certificate was encrypted with SHA1 and that new with SHA256.
Since the authentication stops working.

On the phones is the latest firmware 30.80.0.95.
CA Certificate = SHA265, 2048 bits, BASE64 export.

Is there not SHA256 encryption support for 802.1x by this Phones?

Thanks for the help,
Torsten
03-09-2016 06:21 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Karl_Yealink Offline
Super Moderator
******

Posts: 673
Joined: Apr 2015
Reputation: 5
Post: #2
RE: T46g & T48G RADIUS 802.1x and SHA256
You can get help from the guide:
http://support.yealink.com/attachmentDow...V80_60.pdf
(This post was last modified: 03-10-2016 03:51 AM by Karl_Yealink.)
03-10-2016 03:51 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Bigmac Offline
Junior Member
**

Posts: 8
Joined: Mar 2016
Reputation: 0
Post: #3
RE: T46g & T48G RADIUS 802.1x and SHA256
Hi Karl,

thanks for your answer.
These instructions I already know - but it does not help.
When T46G works authentication only when the phone has received an IP already in the network, and subsequently the authentication is turned on the switch.
After restarting the T46G Phone the authentication fails.

At T48G it does not work at all.

As already said, certificate with the SHA1 it has always worked.

Does somebody has any idea?

Thanks and regards,
Torsten
03-10-2016 05:01 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Karl_Yealink Offline
Super Moderator
******

Posts: 673
Joined: Apr 2015
Reputation: 5
Post: #4
RE: T46g & T48G RADIUS 802.1x and SHA256
Hi Torsten,

I have clients use the CA encrypted with sha256, and it can work normally in V80 version.

Can you try other 802.1x Mode to test again?
And check the time of CA, will it out of date?

If it still can't work, please help us to get the syslog, we can check something from them.
You can know how to do from the FAQ: http://support.yealink.com/faq/faqInfo?id=311
03-11-2016 03:47 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Bigmac Offline
Junior Member
**

Posts: 8
Joined: Mar 2016
Reputation: 0
Post: #5
RE: T46g & T48G RADIUS 802.1x and SHA256
(03-11-2016 03:47 AM)Yealink_Karl Wrote:  Hi Torsten,

I have clients use the CA encrypted with sha256, and it can work normally in V80 version.

Can you try other 802.1x Mode to test again?
And check the time of CA, will it out of date?

If it still can't work, please help us to get the syslog, we can check something from them.
You can know how to do from the FAQ: http://support.yealink.com/faq/faqInfo?id=311

Hi Karl,

Thanks for help me.

MD5 works fine, bit isn't save.
The Phone doesn't accept the CA-Cert from RADIUS (please see picture in Attachments)

Best regards,
Torsten


Attached File(s) Thumbnail(s)
   
03-14-2016 11:04 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Karl_Yealink Offline
Super Moderator
******

Posts: 673
Joined: Apr 2015
Reputation: 5
Post: #6
RE: T46g & T48G RADIUS 802.1x and SHA256
Would you please mind send the CA-Cert and syslog to me.
I will sumbit this problem to our R&D to do an anaylze.
If you don't want to make the info public, you can send a email to me(karl@yealink.com)

Note that you need to tell me the forum link in the email, so I can know the detail problem.
03-18-2016 04:21 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Bigmac Offline
Junior Member
**

Posts: 8
Joined: Mar 2016
Reputation: 0
Post: #7
RE: T46g & T48G RADIUS 802.1x and SHA256
Hi Karl,

When I take a new T46G (freshly unpacked) and install it through the provisioning, the 802.1x RADIUS with SHA256 Cert works immediately.
On phones that had previously installed the old SHA1 Cert it does not work after changing to the new SHA256 Cert.

If the old Cert not clean from memory?
Or still exist entries for the old cert?
(Back to Factory defaults dosn't help)

BR,
Torsten
(This post was last modified: 03-22-2016 08:11 PM by Bigmac.)
03-22-2016 07:01 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Karl_Yealink Offline
Super Moderator
******

Posts: 673
Joined: Apr 2015
Reputation: 5
Post: #8
RE: T46g & T48G RADIUS 802.1x and SHA256
Suggest that you can upgrade the firmware again and reset the phone then test again.
You can download the latest firmware from the link: http://support.yealink.com/documentFront...ateId=1313
03-23-2016 04:56 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Bigmac Offline
Junior Member
**

Posts: 8
Joined: Mar 2016
Reputation: 0
Post: #9
RE: T46g & T48G RADIUS 802.1x and SHA256
Hi Karl,

Thanks for your answer.

The status of my tests:
A new T46G (fresh out of the package) with firmware 28.80.0.95 works with 802.1x & SHA256

A new T48G (fresh out of the package) with firmware 35.80.0.95 does not work with 802.1x & SHA256
-> Back to firmware 35.80.0.70 and behold - it works.

Fixed: (Used T48G (previously with SHA1 certificate) does not work, no matter what firmware is installed. Reset and installing firmware not change anything.)
-> Factory defaults by Menu on Phone has fix the problem.

Only problem with the firmware 35.80.0.95 on the T48G persists.
The firmware 35.80.0.70 works fine.

Best regards,
Torsten
(This post was last modified: 03-29-2016 08:38 PM by Bigmac.)
03-29-2016 05:22 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Karl_Yealink Offline
Super Moderator
******

Posts: 673
Joined: Apr 2015
Reputation: 5
Post: #10
RE: T46g & T48G RADIUS 802.1x and SHA256
Hi Torsten,

Suggest that you can use the 35.80.0.70 right now.
I will submit this issue to our R&D to know.
Thank you for your info.
04-08-2016 03:00 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Best way to manage line keys on multiple T48G/S sani390 0 3,485 07-01-2021 02:06 PM
Last Post: sani390
  Change standard outgoing line on T46G oestersund 1 6,555 12-15-2018 09:58 PM
Last Post: support2
  Call Park Mode transfer on T48G jasonblewis 2 11,049 11-09-2017 01:26 AM
Last Post: Aishion_Yealink
  T48G not connecting to Skype Lisa H 0 4,578 10-16-2017 03:17 AM
Last Post: Lisa H
  can't setup openvpn with t48g zzz 8 24,389 07-18-2017 09:04 AM
Last Post: sj
  T46G: How to deactivate Live Dialpad totally? Werner1959 6 16,530 03-05-2017 08:21 PM
Last Post: Werner1959
  T48G - busy tone for a second incomming call Dirk 8 20,036 01-17-2017 05:36 PM
Last Post: complex1
  T46G with exp40 Paulo Batista 2 9,074 11-06-2016 01:57 AM
Last Post: CWR
  T46G eaches only incoming calls, no outgoing calls Ddorf 2 8,359 10-27-2016 12:46 AM
Last Post: anonymous1712222627012
  T46G Hostname not registering on DHCP fraukas 2 12,679 10-27-2016 12:34 AM
Last Post: anonymous1712222627012

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Contact Us   Yealink   Return to Top   Return to Content   Lite (Archive) Mode   RSS Syndication