4: Enabling Security
54 Verint Video Solutions
Building a Secure System
SSL is a commonly used protocol for managing the security of
message transmission on an IP network. SSL uses the
public-and-private key encryption system from RSA, which also
includes the use of a digital certificate; therefore, each
SSL-enabled device comes with its own unique SSL certificate.
The SSL protocol secures the following data: I/O, serial port,
and VSIP communication. It does not apply to audio and video
transmission.
For increased security, Nextiva devices and SConfigurator use
an SSL passkey. This passkey must be the same in all devices
and in SConfigurator to establish a secure system. It is strongly
recommended to change the default passkey (the empty string)
prior to putting the devices in production.
On top of the SSL passkey, SConfigurator manages a list of
devices it trusts. Therefore, fake devices with SSL certificates
or hacked SConfigurator programs will not be able to break into
your secure system.
To build a secure system:
1. Create the list of devices that will work in the secure
context (see page 7).
This list is called the trusted list, and the enclosed devices,
the trusted devices.
2. Set up the default secure VSIP connection between
SConfigurator and a new device (see page 55).
3. For a video server, change its SSL passkey (see page 21)
and VSIP port (see page 20).
4. For an S1100w wireless transmitter, change its wireless
passkey (see page 29).
5. For an outdoor wireless bridge:
a. Change its SSL passkey (see page 21) and VSIP port
(see page 20).
b. Change its wireless passkey (see page 29).
6. Add the device to the trusted list (see page 56).
7. Enable security in the device (see page 21).
Komentáře k této Příručce