Identity certificate descriptions

Last Updated : May 26, 2021 |
Prolog information
Multiple identity certificates exist on Avaya Breeze® platform.
Service name
To/from
Protocol
Port
Support 2048 key length and SHA2 signature
Notes
Security Module HTTPS
Secure HTTP interfaces for connections into snap-ins.
HTTPS
Port 443 on Avaya Breeze® platform.
Yes
Incoming secure REST and HTTP traffic use this certificate. Outgoing connections use the WebSphere certificate.
Security Module SIP
SIP TLS connections between Avaya Breeze® platform and external servers. For example, Session Manager.
SIP
Default port 5061 on Avaya Breeze® platform. Other ports also supported.
Yes
Any product that needs a SIP TLS link to Avaya Breeze® platform.
WebSphere
IP TLS connection between the Security Module and the WebSphere (WAS) container and outgoing communications from snap-ins.
SIP
Internal port 15061
Yes
This certificate is only used for internal connections between WAS and SECMOD and for snap-ins that send requests to external clients.
SPIRIT
SAL server on System Manager
HTTPS
Avaya Breeze® platform ephemeral port 22 connections to SMGR port 443 (HTTPS)
Yes
Management (JBOSS)
Connections between System Manager and Avaya Breeze® platform for management. For example, RMI/JMX and DRS replication.
JMX, RMI, HTTPS
JMX for DRS. Avaya Breeze® platform port 2009 RMI Avaya Breeze® platform port 11099, JMX Avaya Breeze® platform port 11100 HTTPS port 443 on SMGR
Yes
Use for both Internal communication and for external access from some snap-ins.
CDB
Connections to Avaya Breeze® platform local cluster DB
TCP/TLS
Port 5433 on Avaya Breeze® platform
Yes
Authorization
Connections to utilize the alternative OAuth-based platform security Framework for all incoming requests that have an OAuth token
Yes
Postgres
Connections to Avaya Breeze® platform local Postgres DB
TCP/TLS
Port 5432 on Avaya Breeze® platform
Yes