cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
550
Views
0
Helpful
1
Replies

Slow ClientKeyExchange on SPA500-series HTTPS requests

gustavolsson
Level 1
Level 1

On HTTPS requests from SPA-500 series phones I'm seeing that it takes the SPA (in this case a 504G) about six seconds to send it's ClientKeyExchange after it has received the server's ServerHelloDone. This is no problem in the case where the request is a provisioning request, but when it's a request in an XMLApplication, it doesn't really work to have the use waiting that long for each request.

I have taken pcap's of this and it's reproducible every time. I see it on both XML- and provisioning-requests.

Would it be possible to speed-up this or is this purely a limitation on CPU or something in the SPA unit?

Thanks in advance!

1 Reply 1

Alberto Montilla
Cisco Employee
Cisco Employee

Dear Gustav;

Yes; it is the client building the key, CPU cycles...

We recommend using https only for those transactions which requires exchange of private data, others should go over http.

Regards

Alberto

Regards;

Alberto

From mobile phone

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: