VoIP: SIP-over-TLS and sRTP: Ascom

Ascom Wireless Solutions (Ascom AB) had the Ascom i75, which they upgraded to SIP in 2007. In the year 2010 with the Ascom i62, they added SDES-sRTP. Still today, this model is sold not only by Ascom but also as Unify OpenStage WL3, Mitel 5624, and innovaphone IP62. In contrast to my other phones, this device cannot be configured via a Web interface but requires computer software for configuration, for example, WinPDM. With that, you can use VoIP/SIP servers like Digium Asterisk or public VoIP/SIP providers. If not specified differently, the navigation path is WinPDM → (tab) Numbers → Menu → Number → Edit parameters.

Last tested firmware

6.1.0
retested with 6.1.2 (13 Mar 2019)

Configuration

Password: admin/changeme
WinPDM → Device → General Administration password
HTTPS: enabled out of the box
Update: WinPDM → (tab) Device → Menu → Device → Upgrade software…
Trust Anchors: WinPDM → (tab) Numbers → Menu → Number → Manage Certificates → (tab) Trust list
SIP-URI User: WinPDM → (tab) Numbers → Menu → Number → New… or Rename… → (Call) number
SIP-URI Host: VoIP → SIP → Primary SIP proxy
SIP-over-TLS: VoIP → SIP → SIP Transport: TLS
SDES-sRTP: VoIP → General → Offer Secure RTP: Yes
which is RTP/SAVP + RTP/AVP

Software Bugs

SHA-2 Digest: does not pick MD5, continues without header Authorization, therefore is not able to register; therefore incompatible with Linphone
DNS-NAPTR: missing
NTP: allows no domain, just IP address
Named Curves: just P-256, no P-384, or X448; questions its AES-256 sRTP support
IP Port Source: not the actual port but 5060 in the SIP headers Via and Contact
Mitigation: unknown; service has to ignore it and re-use the TCP based connection instead

Security

Bugs: DNS-SRV redirection disables Hostname Validation,
missing TLS_ECDHE_[RSA|ECDSA]_WITH_AES_128_GCM_SHA256
Responsible Disclosure: no way found
Firmware Update: missing Automation
missing Newsletter

Miscellaneous

Model Range

Power Supply

5 V ?.? A, Desktop Charger (proprietary USB interface)

back to the other phones.