Identity certificate descriptions

Last Updated : May 26, 2021 |

Multiple identity certificates exist on Avaya Breeze® platform.

Service name

To/from

Protocol

Port

Support 2048 key length and SHA2 signature

Notes

Security Module HTTPS

Secure HTTP interfaces for connections into snap-ins.

HTTPS

Port 443 on Avaya Breeze® platform.

Yes

Incoming secure REST and HTTP traffic use this certificate. Outgoing connections use the WebSphere certificate.

Security Module SIP

SIP TLS connections between Avaya Breeze® platform and external servers. For example, Session Manager.

SIP

Default port 5061 on Avaya Breeze® platform. Other ports also supported.

Yes

Any product that needs a SIP TLS link to Avaya Breeze® platform.

WebSphere

IP TLS connection between the Security Module and the WebSphere (WAS) container and outgoing communications from snap-ins.

SIP

Internal port 15061

Yes

This certificate is only used for internal connections between WAS and SECMOD and for snap-ins that send requests to external clients.

SPIRIT

SAL server on System Manager

HTTPS

Avaya Breeze® platform ephemeral port 22 connections to SMGR port 443 (HTTPS)

Yes

Management (JBOSS)

Connections between System Manager and Avaya Breeze® platform for management. For example, RMI/JMX and DRS replication.

JMX, RMI, HTTPS

JMX for DRS. Avaya Breeze® platform port 2009 RMI Avaya Breeze® platform port 11099, JMX Avaya Breeze® platform port 11100 HTTPS port 443 on SMGR

Yes

Use for both Internal communication and for external access from some snap-ins.

CDB

Connections to Avaya Breeze® platform local cluster DB

TCP/TLS

Port 5433 on Avaya Breeze® platform

Yes

Authorization

Connections to utilize the alternative OAuth-based platform security Framework for all incoming requests that have an OAuth token

Yes

Postgres

Connections to Avaya Breeze® platform local Postgres DB

TCP/TLS

Port 5432 on Avaya Breeze® platform

Yes