Replacing an identity certificate with a certificate issued by the System Manager CA

Last Updated : Nov 11, 2025 |
Prolog information
This procedure describes how to replace an Avaya Breeze® platform SIP identity certificate with a certificate signed by the System Manager CA. For example, if you are using a demo certificate, you can replace it with an identity certificate signed by the System Manager CA.
  1. Obtain the System Manager root CA certificate.
  2. Deploy the System Manager root CA certificate on peer devices that connect SIP TLS to Avaya Breeze® platform.
    1. Identify all the peer servers that connect to Avaya Breeze® platform through SIP over TLS.
      ADDITIONAL INFORMATION:
      An example of a peer server is Session Manager.
    2. Deploy the System Manager root CA certificate following the peer server documentation on how to deploy the trusted CA certificate on the respective Trust Stores.
  3. Replace the SIP identity certificate with a certificate issued by the System Manager CA,
  4. Activate the new SIP identity certificate.
  5. Verify that the SIP TLS connections are now using the new identity certificate.
  6. In System Manager, click Elements Session ManagerSystem StatusSIP Entity Monitoring.
  7. Verify that the link status is UP for Avaya Breeze® platform entities that are TLS connected.