Polycom CX5500 Unified Conference Station Administrator’s Guide 1.1.0
Polycom, Inc. 304
<srtp/>
As per RFC 3711, you cannot turn off authentication of RTCP. The table SRTP Parameters lists SRTP
parameters.
SRTP Parameters
sec.srtp.answerWithNewKey
If 0, a new key is not provided when answering a call. If 1, a new key is provided when answering a call.
If 0, the phone always declines SRTP offers. If 1, the phone accepts SRTP offers. Note: The defaults for SIP
3.2.0 was 0 when Null or not defined.
0, positive integer
minimum 1024 or
power of 2 notation
The lifetime of the master key used for the cryptographic parameter in SDP. The value specified is the number of
SRTP packets. If 0, the master key lifetime is not set. If set to a valid value (at least 1024, or a power such as
2^10), the master key lifetime is set. When the lifetime is set, a re-invite with a new key will be sent when the
number or SRTP packets sent for an outgoing call exceeds half the value of the master key lifetime. Note: Setting
this parameter to a non-zero value may affect the performance of the phone.
The master key identifier (MKI) is an optional parameter for the cryptographic parameter in the SDP that uniquely
identifies the SRTP stream within an SRTP session. MKI is expressed as a pair of decimal numbers in the form:
|mki:mki_length| where mki is the MKI value and mki_length its length in bytes. If 1, a four-byte MKI
parameter is sent within the SDP message of the SIP INVITE / 200 OK. If 0, the MKI parameter is not sent.
The length of the master key identifier (MKI), in bytes. Microsoft Lync offers 1-byte MKIs.
sec.srtp.mki.startSessionAtOne
If set to 1, use an MKI value of 1 at the start of an SDP session. If set to 0, the MKI value will increment for each
new crypto key.
If 1, the phone includes a secure media stream description along with the usual non-secure media description in
the SDP of a SIP INVITE. This parameters applies to the phone initiating (offering) a phone call. If 0, no secure
media stream is included in SDP of a SIP invite.
sec.srtp.offer.HMAC_SHA1_32
1
If 1, a crypto line with the AES_CM_128_HMAC_SHA1_32 crypto-suite will be included in offered SDP. If 0, the
crypto line is not included.
sec.srtp.offer.HMAC_SHA1_80
1
If 1, a crypto line with the AES_CM_128_HMAC_SHA1_80 crypto-suite will be included in offered SDP. If 0, the
crypto line is not included.