Certificate handling

Last Updated : Dec 06, 2021 |
Prolog information
TLS or DTLS protects the following types of connections between a Device Adapter node and other solution components:
  • UNIStim signaling between an endpoint and the Device Adapter node.
    • The endpoint initiates the connection.
    • The Device Adapter node acts as the DTLS server and presents its certificate to the endpoint.
    • The endpoint acts as the DTLS client. The endpoint may be requested to authenticate and present its certificate to the Device Adapter node.
  • HTTPS signaling between a Device Adapter node and a PPM node.
    • The Device Adapter node initiates the connection.
    • The PPM node acts as the TLS server and presents its certificate to the Device Adapter node.
    • The Device Adapter node acts as the TLS client. The node may be requested to authenticate and present its certificate to the PPM node.
  • SIP signaling between a Device Adapter node and a Session Manager node.
    • The Device Adapter node initiates the connection.
    • The Session Manager node acts as the TLS server and must present its certificate to the Device Adapter node.
    • The Device Adapter node acts as the TLS client. The node may be requested to authenticate and present its certificate to the Session Manager node.
Note:
TLS 1.3 support is not available for customers who have installed Avaya Breeze® snap-ins such as the Avaya Device Adapter.
Identity and trust management are important for these connections to be successful. Device Adapter relies on the certificate management provided by the Avaya Breeze® platform. The following identity and trusted certificate pairs are relevant to the operation of Device Adapter:
  • Security Module HTTPS identity and trusted certificates for UNIStim and HTTPS secure connections.
  • Security Module SIP identity and trusted certificates for SIP secure connections.
These certificates are made available to Device Adapter for secure communications when Device Adapter is installed on an Avaya Breeze® platform server.
Note:
If you modify any of the Avaya Breeze® platform identity certificates after Device Adapter is installed, you must restart Avaya Breeze® platform.
If you modify any of the Avaya Breeze® platform trusted certificates after Device Adapter is installed, you need not restart Avaya Breeze® platform.
Reinstallation of Device Adapter on the affected Avaya Breeze® platform cluster is not required. Device Adapter automatically applies the changes and restarts the dsa, tps, and csv services within 5 minutes after you modify the certificates. This procedure will not impact the cluster administration data.
This is service impacting. Avaya recommends that you modify the preceding identity or trusted certificates on Avaya Breeze® platform during the maintenance window to minimize the impact on endpoint registration and call handling.