Replacing an identify certificate with a System Manager CA certificate

Last Updated : Nov 11, 2025 |
Prolog information
You can replace an Avaya Breeze® platform identity certificate with a certificate signed by the System Manager CA.
Important:
Peer servers, such as Session Manager, need to trust the System Manager root CA certificate before you replace a SIP or HTTP certificate. Failure to do so can result in a loss of communication between devices.
Note:
Avaya Breeze® platform is initially deployed with certificates generated by the System Manager CA that lack necessary values in the SAN for the SIP and HTTPS certificates. The user is required to update the SIP and HTTPS certificates from the System Manager GUI to include the security module IP/FQDN in the SAN field. Other Avaya Aura® servers now require this information when establishing trust with Avaya Breeze® platform.
  1. In System Manager, click Services Inventory Manage Elements.
  2. Select the appropriate Avaya Breeze® platform from the list and click More Actions.
  3. Select Configure Identity Certificates.
  4. On the Identity Certificates page, select the specific service.
  5. Click Replace.
  6. On the Replace Identity Certificate page, select Replace this Certificate with Internal CA Signed Certificate.
  7. Select the Common Name (CN) check box.
  8. Enter the host name or IP address.
  9. For the securitymodule_sip or securitymodule_http identity certificates, enter the hostname or IP address of the security module.
    ADDITIONAL INFORMATION:
    The address is the same as the SIP entity address. Where possible, use hostnames instead of IP addresses.
  10. Select RSA for the Key Algorithm.
  11. Select 2048 or 4096 as the Key Size.
  12. For the securitymodule_sip or securitymodule_http identity certificate, select the DNS Name check box and enter the Fully Qualified Domain Name of the security module interface.
    ADDITIONAL INFORMATION:
    You can enter multiple SIP domains using commas (no spaces), such as avaya.com,company.com,xyz.com.
  13. For the Security Module SIP or Security Module HTTP identity certificates, select the IP Address check box and enter the security module IP address (the SIP entity address).
    ADDITIONAL INFORMATION:
    For the WebSphere or Management identity certificates, it is not necessary to enter an IP address. Leave the IP address unchecked.
  14. For the Security Module SIP identity certificate, select the URI checkbox and enter the SIP domain preceded by sip: schema. You can enter multiple URIs using commas (no spaces), such as sip:avaya.com,sip:company.com,sip:xyz.com.
    ADDITIONAL INFORMATION:
    RFC5922 recommends Subject Alternative Name (SAN) extension entries of the URI type and the SIP scheme over DNS type entries. Avaya SIP Endpoints currently only support the DNS type entries. Use both DNS and URI entries to cover third party SIP devices which may require them.
  15. Click Commit.