cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
0
Helpful
1
Replies

Slow ClientKeyExchange on SPA500-series HTTPS requests

gustavolsson
Level 1
Level 1

On HTTPS requests from SPA-500 series phones I'm seeing that it takes the SPA (in this case a 504G) about six seconds to send it's ClientKeyExchange after it has received the server's ServerHelloDone. This is no problem in the case where the request is a provisioning request, but when it's a request in an XMLApplication, it doesn't really work to have the use waiting that long for each request.

I have taken pcap's of this and it's reproducible every time. I see it on both XML- and provisioning-requests.

Would it be possible to speed-up this or is this purely a limitation on CPU or something in the SPA unit?

Thanks in advance!

1 Reply 1

Alberto Montilla
Cisco Employee
Cisco Employee

Dear Gustav;

Yes; it is the client building the key, CPU cycles...

We recommend using https only for those transactions which requires exchange of private data, others should go over http.

Regards

Alberto

Regards;

Alberto

From mobile phone