Multiple identity certificates exist on Avaya Breeze® platform.
|
Service name
|
To/from
|
Protocol
|
Port
|
Support 2048 key length and SHA2 signature
|
Notes
|
|
Security Module HTTPS
|
Secure HTTP interfaces for connections into snap-ins.
|
HTTPS
|
Port 443 on Avaya Breeze® platform.
|
Yes
|
Incoming secure REST and HTTP traffic use this certificate. Outgoing connections use the WebSphere certificate.
|
|
Security Module SIP
|
SIP TLS connections between Avaya Breeze® platform and external servers. For example, Session Manager.
|
SIP
|
Default port 5061 on Avaya Breeze® platform. Other ports also supported.
|
Yes
|
Any product that needs a SIP TLS link to Avaya Breeze® platform.
|
|
WebSphere
|
IP TLS connection between the Security Module and the WebSphere (WAS) container and outgoing communications from snap-ins.
|
SIP
|
Internal port 15061
|
Yes
|
This certificate is only used for internal connections between WAS and SECMOD and for snap-ins that send requests to external clients.
|
|
SPIRIT
|
SAL server on System Manager
|
HTTPS
|
Avaya Breeze® platform ephemeral port 22 connections to SMGR port 443 (HTTPS)
|
Yes
|
|
|
Management (JBOSS)
|
Connections between System Manager and Avaya Breeze® platform for management. For example, RMI/JMX and DRS replication.
|
JMX, RMI, HTTPS
|
JMX for DRS. Avaya Breeze® platform port 2009 RMI Avaya Breeze® platform port 11099, JMX Avaya Breeze® platform port 11100 HTTPS port 443 on SMGR
|
Yes
|
Use for both Internal communication and for external access from some snap-ins.
|
|
CDB
|
Connections to Avaya Breeze® platform local cluster DB
|
TCP/TLS
|
Port 5433 on Avaya Breeze® platform
|
Yes
|
|
|
Authorization
|
Connections to utilize the alternative OAuth-based platform security Framework for all incoming requests that have an OAuth token
|
|
|
Yes
|
|
|
Postgres
|
Connections to Avaya Breeze® platform local Postgres DB
|
TCP/TLS
|
Port 5432 on Avaya Breeze® platform
|
Yes
|
|