<div>Hi abaci,</div><div><br></div>IMHO, start with encrypted config files. Then, I also see some ATA with password option which means login sessions can be setup with your provisioning servers for more security.<br><br><div>
/nandy<div><br><div class="gmail_quote">On Mon, Nov 12, 2012 at 7:35 AM, Abaci <span dir="ltr"><<a href="mailto:abaci64@gmail.com" target="_blank">abaci64@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
This question is not specific to FreeSWITCH, just a general question<br>
that I would like to get feedback from other FreeSWITCH users.<br>
I'm thinking of setting up phone provisioning via http, my question is<br>
how to make this setup secure. say my provisioning server will listen on<br>
<a href="https://myserver.com" target="_blank">https://myserver.com</a> and a phone with the mac address 00-15-65-22-F4-23<br>
will try to pull the config as <a href="https://myserver.com" target="_blank">https://myserver.com</a> /00156518425Dhow do<br>
I prevent hackers from trying to get config files using a brute force<br>
attack. is there any standard way of securing against these types of<br>
attacks?<br>
<br>
_________________________________________________________________________<br>
Professional FreeSWITCH Consulting Services:<br>
<a href="mailto:consulting@freeswitch.org">consulting@freeswitch.org</a><br>
<a href="http://www.freeswitchsolutions.com" target="_blank">http://www.freeswitchsolutions.com</a><br>
<br>
FreeSWITCH-powered IP PBX: The CudaTel Communication Server<br>
<a href="http://www.cudatel.com" target="_blank">http://www.cudatel.com</a><br>
<br>
Official FreeSWITCH Sites<br>
<a href="http://www.freeswitch.org" target="_blank">http://www.freeswitch.org</a><br>
<a href="http://wiki.freeswitch.org" target="_blank">http://wiki.freeswitch.org</a><br>
<a href="http://www.cluecon.com" target="_blank">http://www.cluecon.com</a><br>
<br>
FreeSWITCH-users mailing list<br>
<a href="mailto:FreeSWITCH-users@lists.freeswitch.org">FreeSWITCH-users@lists.freeswitch.org</a><br>
<a href="http://lists.freeswitch.org/mailman/listinfo/freeswitch-users" target="_blank">http://lists.freeswitch.org/mailman/listinfo/freeswitch-users</a><br>
UNSUBSCRIBE:<a href="http://lists.freeswitch.org/mailman/options/freeswitch-users" target="_blank">http://lists.freeswitch.org/mailman/options/freeswitch-users</a><br>
<a href="http://www.freeswitch.org" target="_blank">http://www.freeswitch.org</a><br>
</blockquote></div><br></div></div>