Provisioning Security

Status
Not open for further replies.

jtrollen

Joined
May 17, 2010
Messages
21
Reaction score
0
I'm in the process of installing and provisioning a handful of phones and it occurred to me that this could be a huge security hole. In theory, I could look on the bottom of a phone to get the MAC address and pull up the provisioning XML file in a web browser with all of the users information. I could then log in as another user if I wanted to. Am I missing something here? This just seems too easy. How are people securing the provisioning XML files?

Thanks,

-John
 
We only allow access to the provisioning area for known IP addresses as source requestor.

I have never tried (but will test it soon now you mention it) putting the config on a non standard port also, which should help.

I dont see any other way that you can secure it to the outside world yet still let phones pick up configuration.
 
Status
Not open for further replies.

Forum statistics

Threads
111,875
Messages
589,516
Members
164,725
Latest member
pat-g