Replacing an identity certificate issued by a third party CA

Last Updated : May 26, 2021 |
Prolog information
Use this procedure to replace an identity certificate issued by a CA other than the System Manager CA. A third party CA can be a commercial vendor, such as VeriSign or Symantec, or an enterprise-run CA maintained by your IT department. You can use this procedure when your third party identity certificate is about to expire and you need to replace it.
  1. Obtain the new SIP identity certificate through a CSR or a PKCS#12 container.
  2. Deploy the trusted third party root CA certificate on Avaya Breeze® platform.
    1. Obtain the root CA certificate from the third party CA PKI administrator.
    2. Add the root CA certificate into the Avaya Breeze® platform SECURITY_MODULE_SIP and WEBSPHERE trust stores.
  3. Deploy the trusted third party root CA certificate on peer devices that connect SIP TLS to Avaya Breeze® platform.
    1. Identity all the peer devices that connect to Avaya Breeze® platform through SIP over TLS. For example, Session Manager.
    2. Obtain the root CA certificate.
    3. Follow the peer device documentation on how to deploy the trusted CA certificates into their respective Trust Stores.
  4. Replace the SIP identity certificate with a third party CA certificate.
  5. Activate the new SIP identity certificate.
  6. Verify the SIP TLS connections are now using the new identity certificate.
  7. In System Manager, click Elements Session ManagerSystem StatusSIP Entity Monitoring.
  8. Verify that the link status is UP for Avaya Breeze® platform entities that are TLS connected.