| | | |
Offset 33778, 298 lines modified | Offset 33778, 14 lines modified |
33778 | ········</configOption> | 33778 | ········</configOption> |
33779 | ······</configObject> | 33779 | ······</configObject> |
33780 | ····</configFile> | 33780 | ····</configFile> |
33781 | ··</configInfo> | 33781 | ··</configInfo> |
33782 | ··<module·language="en_US"·name="agent"> | 33782 | ··<module·language="en_US"·name="agent"> |
33783 | ····<support_level>extended</support_level> | 33783 | ····<support_level>extended</support_level> |
33784 | ··</module> | 33784 | ··</module> |
33785 | ··<configInfo·name="res_stir_shaken"·language="en_US"> | |
33786 | ····<synopsis>STIR/SHAKEN·module·for·Asterisk</synopsis> | |
33787 | ····<configFile·name="stir_shaken.conf"> | |
33788 | ······<configObject·name="attestation"> | |
33789 | ········<synopsis>STIR/SHAKEN·attestation·options</synopsis> | |
33790 | ········<configOption·name="global_disable"·default="false"> | |
33791 | ··········<synopsis>Globally·disable·verification</synopsis> | |
33792 | ········</configOption> | |
33793 | ········<configOption·name="private_key_file"·default=""> | |
33794 | ··········<synopsis>File·path·to·a·certificate</synopsis> | |
33795 | ········</configOption> | |
33796 | ········<configOption·name="public_cert_url"·default=""> | |
33797 | ··········<synopsis>URL·to·the·public·certificate</synopsis> | |
33798 | ··········<description> | |
33799 | ············<para>Must·be·a·valid·http,·or·https,·URL.</para> | |
33800 | ··········</description> | |
33801 | ········</configOption> | |
33802 | ········<configOption·name="attest_level"> | |
33803 | ··········<synopsis>Attestation·level</synopsis> | |
33804 | ········</configOption> | |
33805 | ········<configOption·name="check_tn_cert_public_url"·default="false"> | |
33806 | ··········<synopsis>On·load,·Retrieve·all·TN's·certificates·and·validate·their·dates</synopsis> | |
33807 | ········</configOption> | |
33808 | ········<configOption·name="send_mky"·default="no"> | |
33809 | ··········<synopsis>Send·a·media·key·(mky)·grant·in·the·attestation·for·DTLS·calls. | |
33810 | » » » » » (not·common)</synopsis> | |
33811 | ········</configOption> | |
33812 | ······</configObject> | |
33813 | ······<configObject·name="tn"> | |
33814 | ········<synopsis>STIR/SHAKEN·TN·options</synopsis> | |
33815 | ········<configOption·name="type"> | |
33816 | ··········<synopsis>Must·be·of·type·'tn'.</synopsis> | |
33817 | ········</configOption> | |
33818 | ········<configOption·name="private_key_file"·default=""> | |
33819 | ··········<synopsis>File·path·to·a·certificate</synopsis> | |
33820 | ········</configOption> | |
33821 | ········<configOption·name="public_cert_url"·default=""> | |
33822 | ··········<synopsis>URL·to·the·public·certificate</synopsis> | |
33823 | ··········<description> | |
33824 | ············<para>Must·be·a·valid·http,·or·https,·URL.</para> | |
33825 | ··········</description> | |
33826 | ········</configOption> | |
33827 | ········<configOption·name="attest_level"> | |
33828 | ··········<synopsis>Attestation·level</synopsis> | |
33829 | ········</configOption> | |
33830 | ········<configOption·name="check_tn_cert_public_url"·default="false"> | |
33831 | ··········<synopsis>On·load,·Retrieve·all·TN's·certificates·and·validate·their·dates</synopsis> | |
33832 | ········</configOption> | |
33833 | ········<configOption·name="send_mky"·default="no"> | |
33834 | ··········<synopsis>Send·a·media·key·(mky)·grant·in·the·attestation·for·DTLS·calls. | |
33835 | » » » » » (not·common)</synopsis> | |
33836 | ········</configOption> | |
33837 | ······</configObject> | |
33838 | ······<configObject·name="verification"> | |
33839 | ········<synopsis>STIR/SHAKEN·verification·options</synopsis> | |
33840 | ········<configOption·name="global_disable"·default="false"> | |
33841 | ··········<synopsis>Globally·disable·verification</synopsis> | |
33842 | ········</configOption> | |
33843 | ········<configOption·name="load_system_certs"·default=""> | |
33844 | ··········<synopsis>A·boolean·indicating·whether·trusted·CA·certificates·should·be·loaded·from·the·system</synopsis> | |
33845 | ········</configOption> | |
33846 | ········<configOption·name="ca_file"·default=""> | |
33847 | ··········<synopsis>Path·to·a·file·containing·one·or·more·CA·certs·in·PEM·format</synopsis> | |
33848 | ··········<description> | |
33849 | ············<para>These·certs·are·used·to·verify·the·chain·of·trust·for·the | |
33850 | » » » » » » certificate·retrieved·from·the·X5U·Identity·header·parameter.··This | |
33851 | » » » » » » file·must·have·the·root·CA·certificate,·the·certificate·of·the | |
33852 | » » » » » » issuer·of·the·X5U·certificate,·and·any·intermediate·certificates | |
33853 | » » » » » » between·them.</para> | |
33854 | ············<para>See·https://docs.asterisk.org/Deployment/STIR-SHAKEN/·for·more·information.</para> | |
33855 | ··········</description> | |
33856 | ········</configOption> | |
33857 | ········<configOption·name="ca_path"·default=""> | |
33858 | ··········<synopsis>Path·to·a·directory·containing·one·or·more·hashed·CA·certs</synopsis> | |
33859 | ··········<description> | |
33860 | ············<xi:include·xpointer="xpointer(/docs/configInfo[@name='res_stir_shaken']/configFile[@name='stir_shaken.conf']/configObject[@name='verification']/configOption[@name='ca_file']/description/node())"/> | |
33861 | ············<para> | |
33862 | ··············For·this·option,·the·individual·certificates·must·be·placed·in | |
33863 | » » » » » » the·directory·specified·and·hashed·using·the | |
33864 | ··············<literal>openssl·rehash</literal> | |
33865 | ··············command. | |
33866 | ············</para> | |
33867 | ············<para>See·https://docs.asterisk.org/Deployment/STIR-SHAKEN/·for·more·information.</para> | |
33868 | ··········</description> | |
33869 | ········</configOption> | |
33870 | ········<configOption·name="crl_file"·default=""> | |
33871 | ··········<synopsis>Path·to·a·file·containing·one·or·more·CRLs·in·PEM·format</synopsis> | |
33872 | ··········<description> | |
33873 | ············<para>If·you·with·to·check·if·the·certificate·in·the·X5U·Identity·header | |
33874 | » » » » » » parameter·has·been·revoked,·you'll·need·the·certificate·revocation | |
33875 | » » » » » » list·generated·by·the·issuer.</para> | |
33876 | ············<para>See·https://docs.asterisk.org/Deployment/STIR-SHAKEN/·for·more·information.</para> | |
33877 | ··········</description> | |
33878 | ········</configOption> | |
33879 | ········<configOption·name="crl_path"·default=""> | |
33880 | ··········<synopsis>Path·to·a·directory·containing·one·or·more·hashed·CRLs</synopsis> | |
33881 | ··········<description> | |
33882 | ············<xi:include·xpointer="xpointer(/docs/configInfo[@name='res_stir_shaken']/configFile[@name='stir_shaken.conf']/configObject[@name='verification']/configOption[@name='crl_file']/description/node())"/> | |
33883 | ············<para> | |
33884 | ··············For·this·option,·the·individual·CRLs·must·be·placed·in | |
33885 | » » » » » » the·directory·specified·and·hashed·using·the | |
33886 | ··············<literal>openssl·rehash</literal> | |
33887 | ··············command. | |
33888 | ············</para> | |
33889 | ············<para>See·https://docs.asterisk.org/Deployment/STIR-SHAKEN/·for·more·information.</para> | |
33890 | ··········</description> | |
33891 | ········</configOption> | |
33892 | ········<configOption·name="untrusted_cert_file"·default=""> | |
33893 | ··········<synopsis>Path·to·a·file·containing·one·or·more·untrusted·cert·in·PEM·format·used·to·verify·CRLs</synopsis> | |
33894 | ··········<description> | |
33895 | ············<para>If·you·with·to·check·if·the·certificate·in·the·X5U·Identity·header | |
33896 | » » » » » parameter·has·been·revoked,·you'll·need·the·certificate·revocation | |
33897 | » » » » » list·generated·by·the·issuer.··Unfortunately,·sometimes·the·CRLs·are·signed·by·a | |
33898 | » » » » » different·CA·than·the·certificate·being·verified.··In·this·case,·you | |
33899 | » » » » » may·need·to·provide·the·untrusted·certificate·to·verify·the·CRL.</para> | |
33900 | ············<para>See·https://docs.asterisk.org/Deployment/STIR-SHAKEN/·for·more·information.</para> | |
33901 | ··········</description> | |
33902 | ········</configOption> | |
33903 | ········<configOption·name="untrusted_cert_path"·default=""> | |
33904 | ··········<synopsis>Path·to·a·directory·containing·one·or·more·hashed·untrusted·certs·used·to·verify·CRLs</synopsis> | |
Max diff block lines reached; 19017/37549 bytes (50.65%) of diff not shown.
|