Troubleshooting certificate validation

Last Updated : Nov 10, 2025 |
Prolog information
Starting with Avaya Breeze® platform version 3.9.0.3, hostname validation is enhanced to require Subject Alternative Name (SAN) entries in all Identity Certificates. Subject Alternative Name (SAN) entries are now mandatory in all Identity Certificates. The Common Name (CN) alone is no longer sufficient when SAN is missing. Ensure that FQDN is resolvable from all systems accessing the Avaya Breeze® platform. The OVA deployment of Avaya Breeze® platform 3.9.0.3 and higher automatically includes the minimum required SAN fields. For servers upgraded from earlier releases (for example, 3.9.0.2), the existing certificates are typically retained. In most cases, no action is required unless the existing Websphere Identity Certificate does not include Avaya Breeze® platform Management FQDN (mgmt-fqdn) and its corresponding IP address in SAN field.
If the certificate in use does not include the required SAN entries, it must be replaced using System Manager (SMGR).

To replace the certificate

  1. Place the Avaya Breeze® platform cluster in the Deny New Service state.
  2. On the System Manager web console, click Services Inventory.
  3. In the navigation pane, click Manage Elements.
  4. On the Manage Elements page, select an element and click More Actions Manage Identity Certificates.
  5. On the Manage Identity Certificates page, select the Websphere certificate that you want to replace.
  6. Click Replace.
  7. On the Replace Identity Certificate page, select Replace this Certificate with Internal CA Signed Certificate.
  8. Click Replace this Certificate with Internal CA Signed Certificate, and do the following:
    1. Select the Common Name (CN) check box and type the common name that is defined in the existing certificate.
    2. Select the key algorithm and key size from the respective fields. System Manager uses the SHA2 algorithm for generating certificates.
    3. In Subject Alternative Name, select the relevant options and enter the Breeze Management FQDN as DNS Name and its corresponding IP addresses.
    4. To replace the identity certificate with the internal CA signed certificate, click Commit.
  9. Repeat this process for each node in the cluster.
  10. After all nodes have been updated, restart the entire Avaya Breeze® platform cluster to apply the new certificates.