Avaya Aura® Device Services can use TLS to communicate with the following deployment components securely:
LDAP server
System Manager
Session Manager
iView
Avaya Spaces
To establish a secure TLS connection, Avaya Aura® Device Services uses digital identity certificates issued by a trusted Certificate Authority (CA). Before establishing a secure connection, Avaya Aura® Device Services verifies that the respective digital certificate is valid and not expired.
Sometimes, CA might revoke a certificate before it expires. For example, if the certificate public key is compromised. If you continue to use a revoked certificate, your TLS connection might be not secure and can be exploited by a malicious actor. To indicate that a certificate was revoked and should no longer be used, CA places this certificate in a Certificate Revocation List (CRL). This list is publicly available through a CRL distribution point URL. CRLs contain various information about revoked certificates, such as the certificate serial number and revocation date and time. Avaya Aura® Device Services automatically downloads CRLs for all CAs that issued certificates used in your deployment to establish secure connections.
Avaya Aura® Device Services uses this data to determine whether a certificate can be used to establish a secure connection with a deployment component. Avaya Aura® Device Services fetches CRLs from CAs once every 24 hours.
Avaya Aura® Device Services writes events related to certificate revocation checks to the AADS_audit.log file.
Note:
Avaya Aura® Device Services does not support certificate revocation checks using the Online Certificate Status Protocol (OCSP).