cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
779
Views
0
Helpful
2
Replies

What digest algorithms VCS supports? Is VCS FIPS certified?

marekjp2450
Level 1
Level 1

I'm using a bunch of VCSes with software version 6.1. I just empirically found that VCS does not support SHA-1 for device registration. From 3 different methods our software supports VCS always selectes MD5, which is not FIPS-compliant. VCS supports SHA-1 for web and SIP communications, so why not for device registration? It would be even more peculiar since 2005 Tandberg Gatekeeper has no problems with accepting both MD5 and SHA-1 hashes.

Am I missing something? I cannot find any explict information about passwords digest methods for device registration, and no way to configure it...

Also, does VCS have FIPS-2 certification?



2 Replies 2

Alok Jaiswal
Cisco Employee
Cisco Employee

Hi Marek,

I think SIP digest authentication with MD5 is defined in SIP RFC 3261. There is a plan for upcoming version of VCS to support FIPS.

Rgds

Alok

marekjp2450
Level 1
Level 1

Alok,

VCS SIP authentication supports SHA1, as does the SSL access to VCS web interface. I'm interested  in "device authentication" in H323 mode. When presented with selection of MD5 and SHA1 VCS always chooses MD5. When I send SHA1 digest, VCS rejects registration.

As I said, the 2005 version of TANDBERG gatekeeper software accepts SHA1 digest, so I've hard time to believe that VCS does not. I would like authoritative answer if this is VCS-side problem (no support for SHA1 for device authentication) or something in my code.

thanks,

Marek

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: