Multiple identity certificates exist on Avaya Breeze® platform.
Service name |
To/from |
Protocol |
Port |
Support 2048 key length and SHA2 signature |
Notes |
Security Module HTTPS |
Secure HTTP interfaces for connections into snap-ins. |
HTTPS |
Port 443 on Avaya Breeze® platform. |
Yes |
Incoming secure REST and HTTP traffic use this certificate. Outgoing connections use the WebSphere certificate. |
Security Module SIP |
SIP TLS connections between Avaya Breeze® platform and external servers. For example, Session Manager. |
SIP |
Default port 5061 on Avaya Breeze® platform. Other ports also supported. |
Yes |
Any product that needs a SIP TLS link to Avaya Breeze® platform. |
WebSphere |
IP TLS connection between the Security Module and the WebSphere (WAS) container and outgoing communications from snap-ins. |
SIP |
Internal port 15061 |
Yes |
This certificate is only used for internal connections between WAS and SECMOD and for snap-ins that send requests to external clients. |
SPIRIT |
SAL server on System Manager |
HTTPS |
Avaya Breeze® platform ephemeral port 22 connections to SMGR port 443 (HTTPS) |
Yes |
|
Management (JBOSS) |
Connections between System Manager and Avaya Breeze® platform for management. For example, RMI/JMX and DRS replication. |
JMX, RMI, HTTPS |
JMX for DRS. Avaya Breeze® platform port 2009 RMI Avaya Breeze® platform port 11099, JMX Avaya Breeze® platform port 11100 HTTPS port 443 on SMGR |
Yes |
Use for both Internal communication and for external access from some snap-ins. |
CDB |
Connections to Avaya Breeze® platform local cluster DB |
TCP/TLS |
Port 5433 on Avaya Breeze® platform |
Yes |
|
Authorization |
Connections to utilize the alternative OAuth-based platform security Framework for all incoming requests that have an OAuth token |
|
|
Yes |
|
Postgres |
Connections to Avaya Breeze® platform local Postgres DB |
TCP/TLS |
Port 5432 on Avaya Breeze® platform |
Yes |
|