--- title: "Provisioning Security Settings Module Documentation" description: "Documentation for Security Settings" --- ## Table of Contents 1. [Navigation & Access](#navigation--access) 2. [Screenshots & Visual Interface](#screenshots--visual-interface) 3. [Module Overview (Technical)](#1-module-overview-technical) 4. [Module Overview (Commercial/Business)](#2-module-overview-commercialbusiness) 5. [Module Overview (End User/Administrator)](#3-module-overview-end-useradministrator) 6. [User Roles & Key Capabilities](#-user-roles--key-capabilities) 7. [Configuration Fields](#4-configuration-fields) 8. [Common Scenarios & Examples](#5-common-scenarios--examples) 9. [Limitations & Important Notes](#6-limitations--important-notes) 10. [Model Context Protocol (MCP) AI Integration](#model-context-protocol-mcp-ai-integration) 11. [Troubleshooting Tips](#7-troubleshooting-tips) 12. [Glossary](#8-glossary) --- ## Navigation & Access To access the Provisioning Security Settings configuration module: 1. Log in to the Ring2All Web Portal (`https:///login`). 2. In the left navigation sidebar, expand **Settings**. 3. Under **Provisioning**, click **Security Settings** (`/settings/provisioning/provisioning-security-settings`). 4. Configure authentication credentials, toggle HTTP Basic Auth enforcement, and click **Save** in the bottom action bar. --- ## Screenshots & Visual Interface ### Provisioning Security & HTTP Basic Authentication Configuration view managing HTTP Basic Authentication credentials (username, password) and enforcement toggles to prevent unauthorized endpoint enumeration and safeguard SIP credentials during auto-provisioning. ![Provisioning Security Settings Form](/screenshots/settings/provisioning/security-settings-form.png) --- ## 1. Module Overview (Technical) ### What Is Provisioning Security Settings? Provisioning Security Settings is a **provisioning authentication module** that configures HTTP Basic Authentication for device configuration requests. It protects provisioning files from unauthorized access. ### Architecture ``` ┌─────────────────────────────────────────────────────────────────┐ │ Provisioning Security Architecture │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ IP Phone │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Device Request │ │ │ │ │ │ │ │ GET /provisioning/AA-BB-CC-DD-EE-FF.cfg │ │ │ │ Authorization: Basic dXNlcjpwYXNz │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Nginx Proxy │ │ │ │ │ │ │ │ Security Enabled? │ │ │ │ ├─ Yes → Validate credentials │ │ │ │ │ ├─ Valid → Serve config file │ │ │ │ │ └─ Invalid → 401 Unauthorized │ │ │ │ │ │ │ │ │ └─ No → Serve config file directly │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ │ │ ▼ │ │ ┌──────────────────────────────────────────────────────────┐ │ │ │ Provisioning Files │ │ │ │ │ │ │ │ /var/www/provisioning/ │ │ │ │ ├─ AA-BB-CC-DD-EE-FF.cfg │ │ │ │ ├─ 11-22-33-44-55-66.cfg │ │ │ │ └─ .htpasswd (generated credentials) │ │ │ │ │ │ │ └──────────────────────────────────────────────────────────┘ │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` --- ## 2. Module Overview (Commercial/Business) ### Business Value Provisioning Security provides **configuration protection**: | Without Security | With Security | |------------------|---------------| | Open access | Auth required | | Config exposure | Protected files | | No credentials | Username/password | | Security risk | Access control | ### Use Cases 1. **Secure Deployments** - Protect device configs - Prevent unauthorized access 2. **Credential Protection** - Hide SIP passwords - Secure extension data 3. **Compliance** - Access control audit - Security requirements 4. **Multi-tenant Security** - Isolated configurations - Per-domain credentials ### Feature Highlights | Feature | Benefit | |---------|---------| | **HTTP Basic Auth** | Standard authentication | | **Enable/Disable** | Toggle security | | **Username/Password** | Simple credentials | | **Nginx Integration** | Web server auth | | **Password File** | Auto-generated htpasswd | --- ## 3. Module Overview (End User/Administrator) ### What Can You Do? - Enable/disable provisioning security - Set authentication username - Set authentication password - Generate htpasswd file - Protect device configurations ### Provisioning Security Interface ``` ┌─────────────────────────────────────────────────────────────────┐ │ Provisioning Security Settings │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ Authentication Settings │ │ │ │ Enable Security (HTTP Basic Auth): ✓ │ │ │ │ Username: [provisioning ] │ │ Username for provisioning authentication │ │ │ │ Password: [•••••••••••• ] │ │ Password for provisioning authentication │ │ │ │ ──────────────────────────────────────────────────────────────│ │ │ │ ⓘ Note: │ │ • Enabling this will require devices to valid authenticate │ │ when requesting configuration files. │ │ • Ensure your Nginx server is configured to use the │ │ generated password file. │ │ │ │ [Save] │ │ │ └─────────────────────────────────────────────────────────────────┘ ``` ### Quick Tips > [!TIP] > **Device Configuration**: Configure matching credentials on phones. > [!TIP] > **Strong Password**: Use complex passwords for security. > [!WARNING] > **Nginx Required**: Ensure Nginx is configured to use the password file. --- ## 🎯 User Roles & Key Capabilities | Role | Key Capabilities & Permissions | Operational Scope | | :--- | :--- | :--- | | **PBX Super Administrator** | • Global HTTP Basic Auth policy governance and enforcement toggles
• Master provisioning username and password management
• Automated `.htpasswd` credential generation and Nginx reverse proxy reload orchestration
• Plaintext endpoint exposure mitigation and TLS encryption enforcement | Platform-Wide | | **Tenant Administrator** | • Read-only inspection of provisioning security enforcement status
• Verification of authentication requirements for company device onboarding
• Coordination with IT teams to distribute provisioning credentials to remote handsets | Domain Scope | | **VoIP Security Officer** | • Audit of provisioning credential complexity and rotation schedules
• Inspection of reverse proxy HTTP authentication logs and 401 Unauthorized anomaly monitoring
• Compliance verification ensuring MAC-based configuration URLs cannot be enumerated | Platform / Security | | **AI Copilot / MCP Agent** | • Diagnostic inspection of provisioning security configuration (`get_provisioning_security_settings`)
• Autonomous verification of authentication requirements prior to generating device configs | Autonomous Assistant | --- ## 4. Configuration Fields ### Authentication Settings | Field | Description | |-------|-------------| | **Enable Security** | Toggle HTTP Basic Auth | | **Username** | Auth username | | **Password** | Auth password | ### Generated Files | File | Purpose | |------|---------| | **.htpasswd** | Apache/Nginx password file | | **Nginx config** | Auth location directive | --- ## 5. Common Scenarios & Examples ### Scenario 1: Enable Security 1. Navigate to Provisioning Security Settings 2. Check "Enable Security (HTTP Basic Auth)" 3. Enter username (e.g., "provisioning") 4. Enter strong password 5. Click Save 6. Configure Nginx to use password file ### Scenario 2: Disable Security 1. Navigate to Provisioning Security Settings 2. Uncheck "Enable Security" 3. Click Save 4. Note: Configs now accessible without auth ### Scenario 3: Change Credentials 1. Navigate to Provisioning Security Settings 2. Update username and/or password 3. Click Save 4. Update credentials on all devices ### Scenario 4: Configure Phones 1. Enable security in web interface 2. On each phone, set provisioning credentials: - Provisioning URL - Username - Password 3. Reboot phones to apply --- ## 6. Limitations & Important Notes ### Technical Notes > [!NOTE] > **Nginx Configuration**: Manual Nginx setup may be required. > [!NOTE] > **Device Support**: All modern IP phones support HTTP Basic Auth. > [!WARNING] > **Credential Update**: Changing credentials requires updating all devices. ### Best Practices 1. **Enable in Production**: Always enable for production deployments 2. **Strong Passwords**: Use complex, unique passwords 3. **HTTPS Recommended**: Use HTTPS to encrypt credentials in transit 4. **Document Credentials**: Keep secure record of credentials 5. **Test After Changes**: Verify devices can still provision ### Nginx Configuration Example ```nginx location /provisioning { auth_basic "Provisioning"; auth_basic_user_file /path/to/.htpasswd; root /var/www; autoindex off; } ``` ### Phone Configuration | Vendor | Setting | |--------|---------| | **Yealink** | Provisioning → Authentication | | **Grandstream** | Maintenance → Upgrade → Auth | | **Polycom** | Config → Provisioning → User/Pass | --- ## Model Context Protocol (MCP) AI Integration The **Provisioning Security Settings** module provides Model Context Protocol (MCP) integration allowing AI Copilots, VoIP onboarding bots, and security compliance tools to audit whether HTTP Basic Authentication is actively enforced on device provisioning URLs. ### Available MCP Telephony Tools | Tool Name | Action Type | Access Level | Description | | :--- | :--- | :--- | :--- | | `get_provisioning_security_settings` | `READ` | `Read-Only` | Retrieves the global auto-provisioning security configuration (whether HTTP Basic Auth is enabled and the configured username). Passwords are permanently redacted for enterprise compliance. | ### Tool Schemas & Input Parameters #### `get_provisioning_security_settings` Audits the global HTTP Basic Auth enforcement status for IP phone provisioning endpoints. ```json { "name": "get_provisioning_security_settings", "description": "Retrieves the global auto-provisioning security configuration (whether HTTP Basic Auth is enabled and the configured username). Passwords are redacted for security.", "parameters": { "type": "object", "properties": {}, "additionalProperties": false } } ``` ### Natural Language Prompt Examples #### English Prompts > 💬 "Is HTTP Basic Auth enabled for auto-provisioning?" > 💬 "Check the provisioning security settings and show me the active authentication username." > 💬 "Audit the provisioning security status to ensure device configuration files are protected." #### Spanish Prompts (Español) > 💬 "¿Está activada la autenticación HTTP Basic para el auto-aprovisionamiento?" > 💬 "Verifica la configuración de seguridad de aprovisionamiento y muestra el usuario configurado." > 💬 "Audita el estado de seguridad para asegurar que los archivos de configuración estén protegidos." ### Enterprise Safeguards & Compliance - **Credential Redaction**: Plaintext passwords and cryptographic hashes are never returned by MCP tools or REST API responses. - **Role-Based Access Control**: Executing `get_provisioning_security_settings` requires administrative privileges under the `auxiliary_devices` MCP permission scope. - **Audit Logging**: Any alteration to HTTP Basic Auth enforcement or credentials is permanently written to the PBX security audit trail with operator identity and source IP. --- ## 7. Troubleshooting Tips ### Common Issues | Symptom | Possible Cause | Solution | |---------|---------------|----------| | 401 Unauthorized | Wrong credentials | Check username/password | | Phones not provisioning | Auth not enabled on phone | Configure phone auth | | htpasswd not found | Path incorrect | Check file location | | Nginx error | Config not reloaded | Reload Nginx | ### Test Authentication ```bash # Test provisioning URL with auth curl -u username:password https://server/provisioning/test.cfg # Test without auth (should fail if enabled) curl https://server/provisioning/test.cfg ``` ### Check htpasswd File ```bash # View htpasswd file cat /path/to/.htpasswd # Verify password (htpasswd tool) htpasswd -v /path/to/.htpasswd username ``` ### Reload Nginx ```bash # Test configuration nginx -t # Reload systemctl reload nginx ``` --- ## 8. Glossary | Term | Definition | |------|------------| | **HTTP Basic Auth** | Standard web authentication | | **htpasswd** | Apache/Nginx password file | | **Provisioning** | Automatic device configuration | | **401 Unauthorized** | Authentication required/failed | | **Credentials** | Username and password pair | --- *Documentation last updated: January 2026*