Oracle SBC Security Guide
srtp-encrypt enabled
srtcp-encrypt enabled
egress-offer-format same-as-ingress
use-ingress-session-params srtcp-encrypt
srtp-auth
srtp-encrypt
mki disabled
key
salt
For mikey-profile, it is needed to define the key-exchange-method and the encryption and authentication
methods used. Also, the “egress-offer-format” is used the same way as the one in sdes-profile. However,
the “use-ingress-session-params” in the mikey-profile is not in use, and is reserved for future use.
(mikey-profile)# show
mikey-profile
name mikey1
key-exchange-method pre-shared
encr-algorithm AES-CM
auth-algorithm HMAC-SHA1-80 HMAC-SHA1-32
shared-secret
mki disabled
egress-offer-format same-as-ingress
use-ingress-session-params
(mikey-profile)#
Security media-security media-sec-policy
Media-sec-policy instructs the SBC how to handle the SDP received/sent under a realm (RTP,
SRTP or any of them) and, if SRTP needs to be used, the sdes/mikey-profile that needs to be
used.
The media-sec-policy should be assigned to a realm under the realm-config configuration.
(media-sec-policy)# show
media-sec-policy
name msp1
pass-through disabled
inbound
profile sdes1
mode srtp
protocol sdes
outbound
profile sdes1
mode srtp
protocol sdes
(media-sec-policy)#
Security ipsec security-policy
The security-policy is the element that creates the security-association inside the SBC, needed to
make the real SRTP encryption/unencryption. Each security-policy created must have a unique
priority.
Comentarios a estos manuales