Provisioning remote access points for use in a telecommunication network. A remote access point contains identity information established during manufacturing; this identity information may be in the nature of a digital
certificate. The identity information is stored in the remote access point, and may be stored in a
Trusted Platform Module if present. When the remote access node is powered up in unprovisioned state, outside the manufacturing environment, it attempts to establish an internet connection via a first wired interface, and queries a user for information representing the TCP /
IP address of its controller via a second wired interface. Once an internet connection is present, and a TCP /
IP address has been provided, the remote access point attempts to connect to the controller at that address. The controller may filter connection requests through a
whitelist of approved remote access points. Once a connection is established, controller and access point exchange and verify each other's identities. This may be done through the exchange and
verification of digital certificates. Provisioning information is downloaded from controller to remote access point and installed. This may be done via a tunnel such as an encrypted tunnel.
Software updates may be applied. The provisioned remote access point is placed in operation.