Replacing an identify certificate with a third party CA certificate

Last Updated : Jun 15, 2021 |
Prolog information
You can replace an Avaya Breeze® platform identity certificate with a certificate issued by a third party CA. A third party CA can be a commercial vendor, such asVeriSign or Symantec, or an enterprise-run CA maintained by your IT department. When the security module SIP certificate changes to the third party certificate, each SIP entity must trust the third party CA.
Important:
Peer servers, such as Session Manager, need to trust the third party root CA certificate before you replace a SIP or HTTP certificate. Failure to do so can result in a loss of communication between devices.
Before you begin
Make sure you have the following:
  • An identity certificate with the correct attributes that is signed by the third party CA. This certificate must be in the PKCS#12 format. The identity certificate attributes are described in the sections below. For example, for the SIP certificate, see Security Module SIP identity certificate attributes.
  • The entire certificate chain which signed the identity certificate. This includes the third party root CA certificate as well as any intermediate CA certificates.
  1. In System Manager, click Services Inventory Manage Elements.
  2. Select the appropriate Avaya Breeze® platform from the list and click More Actions.
  3. Select Configure Identity Certificates from the drop-down menu.
  4. On the Identity Certificates page, select the specific service.
    For example, Security Module SIP or Security Module HTTPS.
  5. Click Replace.
  6. On the Replace Identity Certificate page, select Import third party PKCS#12 file.
  7. When prompted to select a file, navigate to the third party signed certificate.
  8. Enter the password in the Password field.
  9. Click Retrieve Certificate.
  10. 10. Click Commit.