New Forum system requires email address which you used to apply for your account to replace your original username. Password stays the same.Please see this post for more details
http://forum.yealink.com/forum/showthread.php?tid=40344

Yealink Test Club has been officially launched. Please visit post below to get detail information. Come and join us!
http://forum.yealink.com/forum/announcements.php?aid=18

We just had the YMCS online and we are also working on the features plan on the future versions, in this regard we are need to hear your voice about the YMCS.
Please visit : http://forum.yealink.com/forum/showthread.php?tid=42322


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Critical V72 Firmware SSL Question
Author Message
dezmd Offline
Junior Member
**

Posts: 1
Joined: Apr 2014
Reputation: 0
Post: #1
Critical V72 Firmware SSL Question
I noticed this in the changelog for Firmware V72 in regards to the SSL certificate preloaded by Yealink on new phones from the factory:

4) The security of Certificate Authority:
It is not allowed for the ordinary user or administrator to view details of the preset
certificate or TLS certificate on the phones from the factory. The certificate cannot be
deleted, copied, edited, exported, or viewed.



Why is the SSL certificate in new 'from factory' phones permanently stored in the phone with no ability for administrators to remove?

I am trying to withhold knee-jerk judgement without more information, but based on the information I've seen so far, this is the reaction you should expect:

If this is in fact the inability to remove this "secret" certificate on new phones that come from the factory with V72+ firmware, this is an absolute show stopper for any enterprise class deployment with these phones. This is a serious security liability for any network that implements these phones. Admins must be able to revoke SSL certificates that may be compromised or untrusted.

Please confirm an ability to delete and replace this certificate by sysadmins.

Thank you for your time.
04-04-2014 10:15 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Post Reply 


Messages In This Thread
Critical V72 Firmware SSL Question - dezmd - 04-04-2014 10:15 AM

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Firmware update for EXP40 Argenture 1 215 07-26-2019 12:33 AM
Last Post: Baron_Yealink
  Firmware upgrade error on T23G acubino 1 244 07-22-2019 03:03 AM
Last Post: Evan_Yealink
Exclamation Downgrade Firmware!! Help!!! manny.garcia@dhitelecom.com 0 394 06-24-2019 02:46 PM
Last Post: manny.garcia@dhitelecom.com
  T27G firmware phnau 1 364 05-21-2019 10:19 AM
Last Post: complex1
  Phones Web UI Not Working after Firmware Update Rockses 0 409 04-09-2019 01:24 PM
Last Post: Rockses
  Will the VP59 have either SfB or Teams firmware ksesock 0 432 02-23-2019 05:38 AM
Last Post: ksesock
  Firmware update failed Utendo 1 1,362 12-17-2018 11:02 AM
Last Post: complex1
  EHS 36 Firmware VOIP 0 545 11-16-2018 07:08 PM
Last Post: VOIP
Question V84 Firmware Model Support Eden 0 612 11-14-2018 02:41 PM
Last Post: Eden
  Firmware url version variables possible? rromano 1 917 08-22-2018 05:28 PM
Last Post: johnkiniston

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Contact Us   Yealink   Return to Top   Return to Content   Lite (Archive) Mode   RSS Syndication