DOCSHUB DOCSHUB
  • Library
  • Avaya Support Site Avaya Learning Blogs Videos & Podcasts Knowledge base Report Product bugs
Deutsch English Español (México) Français Français (Canada) Italiano Magyar Nederlands Português (Brasil) Русский עברית العربية 中文(简体) 中文(繁體) 日本語 한국어
Login
DOCSHUB DOCSHUB
  • Library
  • Avaya Support Site Avaya Learning Blogs Videos & Podcasts Knowledge base Report Product bugs
  • Deutsch English Español (México) Français Français (Canada) Italiano Magyar Nederlands Português (Brasil) Русский עברית العربية 中文(简体) 中文(繁體) 日本語 한국어
Login

Deploying Avaya Aura® Device Services

Table of Contents

Type to filter navigation items by title
  • Legal
  • Introduction
    • Purpose
    • Changes to platform support
    • Change history
  • Avaya Aura Device Services overview
    • New in Avaya Aura Device Services Release 10.2.1.1
    • New in Avaya Aura Device Services Release 10.2.1
    • New in Avaya Aura Device Services Release 10.2.0.1
    • New in Avaya Aura Device Services Release 10.2
    • Solution topology
    • Geographically distributed system topology
    • Automatic configuration flow
    • Components
    • Data retention
    • Data encryption
    • Deployments with Avaya Aura and without Avaya Aura
  • Planning
    • Required skills and knowledge
    • Data required for installation
    • Virtual machine requirements
      • Supported hardware for VMware
      • Supported hardware for ASP R6.0.x (KVM on RHEL 8.10)
      • Supported servers
      • Avaya Aura Device Services support for Avaya Solutions Platform and Avaya Common Server Release 3
      • Software requirements
      • Supported ESXi version
      • Supported ASP R6.0.x (KVM on RHEL 8.10) version
      • Avaya Aura Device Services virtual machine resource requirements
      • Requirements for a host machine for Hyper-V deployments
      • Resource profile specifications for Microsoft Azure virtual machines
      • Resource profile specifications for Google Cloud Platform virtual machines
      • Resources profile specifications for Avaya Aura Device Services on Amazon Web Services
    • Virtual disk volume specifications
    • Networking considerations for Amazon Web Services
      • Connection types
    • Considerations for migrating from a standalone to a cluster environment
    • System Manager geographic redundancy
    • Considerations for large cluster deployments
      • Data center topology configuration in System Manager
      • Network latency requirements
      • Considerations for geographically distributed systems
    • Utility Server deployment considerations
    • LDAP authentication domain requirements
    • Third-party CA-signed certificates
      • Certificates required for an Avaya Aura environment
        • Configuring third-party identity certificates for System Manager
      • Certificates required for an environment without Avaya Aura
    • Cassandra clustering configuration on Avaya Aura Device Services
    • Cassandra clustering and data replication configuration on System Manager
      • Checklist for Cassandra clustering configuration on Session Manager
      • Adding a data center
      • Assigning Session Manager to a data center on System Manager 8.x
      • Assigning Session Manager to a data center on System Manager 10.x or later
    • External load balancer requirements
      • Nginx load balancer requirements
      • Port configuration for an external load balancer
    • Prerequisites for SSO configuration
      • Prerequisites for SAML v2.0 and OAuth2 SSO configuration
      • Prerequisites for Device Authorization Flow configuration
      • Prerequisites for Workspaces SSO configuration
    • Configuration tools and utilities
    • Characters supported for Avaya Aura Device Services passwords
    • Aliases
      • app commands
      • cdto commands
    • System layer commands
      • sys secconfig command
      • sys versions command
      • sys volmgt command
      • sys smcvemgt command
      • sys ipv6config command
      • passwdrules command
      • Data encryption commands
        • encryptionPassphrase command
        • encryptionRemoteKey command
        • encryptionLocalKey command
        • encryptionStatus command
    • Using the Tmux utility
  • Initial setup
    • Deployment methods
    • Downloading software from PLDS
    • Changing the administrative user password during the first logon
  • Initial setup for OVA deployments
    • Installation checklist for OVA-based deployments
    • VMware deployment options
      • Deploying the Avaya Aura Device Services OVA using the vSphere Client
        • VM Deployment Configuration Parameters, Network Parameters, and Data Encryption field descriptions
      • Deploying the Avaya Aura Device Services OVA using the Host Client connected directly to the ESXi host
      • Deploying the Avaya Aura Device Services OVA through Solution Deployment Manager from System Manager
        • Application Management field descriptions
    • Logging on to the Avaya Aura Device Services console on VMware
    • Enabling IPv6 support at the system layer
    • Enabling FIPS mode
      • Disabling FIPS mode
    • Enabling additional STIG hardening
      • Disabling additional STIG hardening
    • Configuring UEFI Secure Boot for OVA-based virtual machines
      • Checking the UEFI Secure Boot status
  • Initial setup for software-only deployments
    • Initial setup for software-only VMware deployments
      • Software-only installation checklist for VMware-based environment
      • Red Hat Enterprise Linux installation
        • Disk partitions for software-only deployments
      • Creating disk partitioning for VMware-based software-only deployments
      • Creating an administrative user
      • Additional packages required by Avaya Aura Device Services
        • Installing additional RHEL 8.4 or RHEL 8.10 packages manually
      • Enabling the Haveged service
      • Enabling FIPS for software-only systems
      • RHEL packages management
        • Enabling required RHEL repositories
      • Installing the system layer
      • Checking the Chrony service status
      • Checking the connection to System Manager and Session Manager
      • Enabling IPv6 support for software-only deployments
    • Initial setup for software-only deployments on Amazon Web Services
      • Software-only installation checklist for Amazon Web Services
      • Prerequisites for software-only deployment on AWS
      • Creating and applying load balancer certificates
      • Creating a key pair
      • Creating security groups
        • Traffic rules for the Avaya Aura Device Services security group
        • Traffic rules for the Utility Server security group
        • Traffic rules for the Avaya Aura Device Services load balancer security group
        • Traffic rules for the Utility Server load balancer security group
      • Installing RHEL 8.4 or RHEL 8.10 on AWS
        • Configuring DNS settings on RHEL
      • Configuring security groups for the secondary eth1 interface
      • Enabling root access
      • Creating disk partitioning for software-only deployments on AWS
      • Prerequisites for installing the system layer on AWS
      • Creating target groups
      • Creating and configuring Elastic load balancers
      • Configuring idle timeout
    • Initial setup for software-only Hyper-V deployments
      • Software-only installation checklist for a Hyper-V virtualized environment
      • Enabling the Hyper-V service
      • Starting Hyper-V Manager
      • Creating a virtual switch
      • Configuring network settings for the virtual switch
      • Creating a new virtual machine on Hyper-V
      • Disabling time synchronization
      • Creating required virtual hard disks for the virtual machine
      • Configuring CPU settings for a Hyper-V virtual machine
      • Configuring Windows Defender firewall rules for ports
      • Creating disk partitioning for software-only deployments on Hyper-V
    • Initial setup for software-only Microsoft Azure deployments
      • Software-only installation checklist for Microsoft Azure
      • Prerequisites for software-only deployment on Microsoft Azure
      • Red Hat Enterprise Linux virtual machine deployment in Microsoft Azure
      • Configuring the secondary network interface on a Microsoft Azure virtual machine
      • Creating required virtual hard disks for a virtual machine
      • Enabling root access
      • Creating disk partitioning for a Microsoft Azure virtual machine
      • Configuring security groups
        • Inbound traffic rules for the Avaya Aura Device Services security group
        • Inbound traffic rules for the Utility Server security group
      • Assigning security groups to network interfaces
      • Prerequisites for installing the system layer on Microsoft Azure
      • Creating a Microsoft Azure load balancer
      • Configuring a Microsoft Azure load balancer
    • Initial setup for software-only Google Cloud Platform deployments
      • Software-only installation checklist for Google Cloud Platform
      • Prerequisites for software-only deployment on Google Cloud Platform
      • Creating VPC peering
      • Configuring firewall rules
        • Firewall rules for Avaya Aura Device Services application network interfaces
        • Firewall rules for Utility Server network interfaces
      • Assigning firewall rules to virtual machines
      • Virtual machine deployment checklist
      • Deploying virtual machines in Google Cloud Platform
      • Reimaging the operating system disk
      • Enabling root access
      • Creating an instance group for load balancers
      • Creating load balancers
      • Creating required virtual hard disks for a virtual machine
      • Enabling LVM on RHEL
      • Creating disk partitioning for a Google Cloud Platform virtual machine
      • Enabling editing of the /etc/hosts file
      • Prerequisites for installing the system layer on Google Cloud Platform
      • Configuring redirection rules for port 443
  • Avaya Aura® Device Services installation
    • Avaya Aura Device Services installation checklist
    • Installing Avaya Aura Device Services
      • Timeout values for Cassandra and Keycloak operations
      • testUser validations
      • Utility Server VIP and FQDN in AWS cluster deployments
    • Installing Avaya Aura Device Services in an environment without Avaya Aura
    • Avaya Aura Device Services cluster installation
      • Installing an Avaya Aura Device Services cluster
      • Initial cluster node installation
      • Installing additional non-seed nodes
      • Installing additional non-seed nodes in an environment without Avaya Aura
      • Configuring RSA public and private keys for SSH connections in a cluster
      • Changing the LDAP parameters after installing an Avaya Aura Device Services cluster
      • Changing the seed node of a cluster
      • Configuring the virtual IP address for Avaya Aura Device Services clusters
      • Configuring an additional seed node
    • Performing a silent installation
    • Enabling the Enhanced Access Security Gateway from the CLI
    • Running the post-installation script
    • Checking for DRS synchronization
    • Creating an AIDE baseline database
    • Changing the default password for automatic backups
    • Uninstalling Avaya Aura Device Services
    • Uninstalling the system layer
  • Initial configuration with the Avaya Aura Device Services configuration utility
    • Configuring Avaya Aura Device Services using the configuration utility
      • Front-end host, System Manager, and certificate configuration
      • LDAP configuration
        • Supported characters for LDAP attributes
      • LDAP advanced parameters
      • Cassandra DB user and password
        • Changing the Cassandra user name and password
      • Clustering configuration
      • Utility Server configuration
      • Advanced configuration
    • Configuring the Avaya Aura Device Services server firewall
    • Configuring additional ports in Avaya Aura Device Services server firewall in 10.x releases
    • Enabling Open LDAP replication
      • Re-enabling Open LDAP replication after removing a node from a cluster
    • OAuth configuration
      • Authorization realm configuration on UC servers and Avaya Workplace Client
      • Configuring Keycloak settings
        • Starting and stopping the Keycloak service
      • Logging in to the Keycloak web administration portal
      • Obtaining the client secret
      • Creating client mapping
      • Modifying the attribute mapping between the third-party identity provider and Keycloak
    • Enabling OAuth database replication in a cluster environment
    • Checklist to Configure Keycloak using a secure LDAP
    • Obtaining LDAP Server Certificate
    • Importing the Certificate into the Keycloak Truststore
    • Configuring LDAPS in Keycloak
  • Configuring Session Manager for cluster environments
    • Managing an incoming call
    • Adding an Avaya Aura Device Services instance to System Manager
    • Pairing Session Manager with an Avaya Aura Device Services node
    • Enabling PPM rate limiting for Session Manager
    • Effect of Session Manager on Avaya Aura Device Services
    • Session Manager operations that impact Avaya Aura Device Services
  • Deploying AADS on ASP R6.0.x (KVM on RHEL 8.10)
    • Deploying Avaya Aura Device Services on ASP R6.0.x (KVM on RHEL 8.10) using KVM Cockpit
  • LDAP settings configuration
    • LDAP authentication domain requirements
    • LDAP attributes replication to the global catalog
    • Installing LDAP schema snap-in
    • Requirements for LDAP attribute values
    • Indexing an attribute
      • List of attributes to index
    • Saving existing LDAP settings
    • Setting up user synchronization with LDAP after deployment
    • LDAP configuration for Microsoft Active Directory
      • Configuring the binding parameters
      • Configuring the authentication parameters
      • Configuring the role search parameters
      • Configuring the internationalization parameters
      • Configuring the user management parameters
    • Multiple authentication and authorization domains
    • Creating groups in LDAP
    • LDAP attribute mapping
      • Configuration and data mapping use cases
      • Changing the PictureURL attribute
    • LDAP configuration best practices
    • LDAP parameter descriptions
  • SNMP server configuration
    • Alarms configuration for System Manager
      • Setting up an SNMPv3 user profile
      • Setting up an SNMP target profile
      • Assigning the SNMPv3 user profile
    • Alarms configuration for a third-party SNMP server
      • Setting up a third-party SNMPv3 server
      • Configuring Avaya Aura Device Services to support a third-party SNMP server
      • Verifying third-party SNMP server operation
  • Reverse proxy configuration
    • Checklist for reverse proxy configuration
    • Creating a CSR
    • TLS certificates field descriptions
    • Creating an end entity
    • Creating the certificate using a CSR
    • Uploading a certificate file
    • Synchronizing and installing certificate in a multi-server deployment
    • Downloading the System Manager PEM certificate
    • Installing a CA certificate
    • Creating a TLS server profile
      • TLS server profile screen field descriptions
    • Creating a TLS client profile
      • TLS client profile screen field descriptions
    • Adding a reverse proxy
    • Overriding port configuration in a cluster
  • Remote access configuration
    • Configuring remote access
    • A10 Thunder Application Delivery Controller Configuration
      • Importing the A10 Client SSL Certificate
      • Importing the A10 Server SSL Certificate
      • Importing the CA root certificate
      • Creating the A10 server SSL template
      • Creating the A10 client SSL template
      • Creating an IP source NAT
      • Creating the Avaya Aura Device Services backend server
      • Creating a virtual server
      • Creating a service group
      • Creating a virtual service
      • Configuring A10 for LDAP searches
      • Configuring A10 for LDAP authentication
  • Troubleshooting
    • Avaya Workspaces Client cannot connect to Avaya Aura Device Services
    • Service unavailable
    • Admin user is not prompted for password in sudo su
    • Avaya Workplace Client cannot connect to Avaya Aura Device Services
    • Avaya Aura Device Services installation fails if the DNS forward and reverse lookup zones are not configured properly
    • Avaya Aura Device Services installation or upgrade fails due to invalid System Manager certificates
    • Avaya Aura Device Services installation fails if third-party certificates are used on other Avaya Aura elements
    • Avaya Aura Device Services installation fails when using third-party CA identity certificates
    • app commands do not work after a failed installation
    • DNS entries disappear from the /etc/resolv.conf file after restarting Avaya Aura Device Services
    • runUserDiagnostics tool
    • Data on Cassandra is corrupted
    • Primary System Manager fails
    • Open LDAP replication fails
    • Open LDAP replication fails if Avaya Aura Device Services uses a custom identity certificate for server interfaces
    • Avaya Workplace Soft Clients are logging out due to a mismatch in the ETAG
  • Resources
    • Documentation
      • Finding documents on the Avaya Support website
      • Avaya Documentation Center navigation
    • Viewing Avaya Mentor videos
    • Support
      • Using the Avaya InSite Knowledge Base
  • Avaya Aura Device Services certificate configuration
    • Command for viewing certificate details
    • Importing the Avaya Aura System Manager trusted certificate
    • Importing third-party CA-signed certificates
    • Importing intermediate CA certificates
    • Generating Certificate Signing Requests
    • Creating a Certificate Signing Request (CSR) using OpenSSL
    • Signing identity certificates for Avaya Aura Device Services using third-party CA certificates
    • Configuring System Manager to trust third-party root CA certificates
    • Viewing the current CA used to sign the Session Manager certificate
    • Importing SIP CA certificate to the Avaya Aura Device Services trust store
    • LDAP certificates
      • Importing a trusted LDAP certificate
    • Configuring the client certificate policy using the command line interface
    • Uploading and hosting CA certificate files on Avaya Aura Device Services server
    • Setting up a TLS link for Avaya Scopia Management
  • LDAP examples and search results
    • Examples of Microsoft Active Directory LDAP property files
    • LDAP search results and referrals
  • FIPS validated cryptographic modules
  • Best Practices for VMware performance and features
    • Timekeeping
    • VMware Tools
    • VMware networking best practices
    • Storage
    • Best Practices for VMware features
      • VMware High Availability
      • VMware vMotion
      • VMware snapshots
    • VMware features supported by Avaya Aura
  • Creating RHEL virtual machine on Nutanix
    • Uploading the RHEL ISO to Nutanix server
    • Installing RHEL on the Nutanix server
  • Virtual Machine Backup (clone) in ASP R6.0.x (KVM on RHEL 8.10)
    • Virtual Machine Backups (clone) as an alternative to snapshots
    • Cloning a Virtual Machine on ASP R6.0.x (KVM on RHEL 8.10)
    • Calculating space for the clone
    • Validating a Virtual Machine Backup (clone)
    • Rolling back using the Virtual Machine Backup (clone)
  • Glossary
    • Cassandra
    • Domain Name System (DNS)
    • Endpoints
    • Fully Qualified Domain Name (FQDN)
    • Network Time Protocol (NTP)
    • Secure Shell (SSH)
    • Simple Network Management Protocol (SNMP)
    • SSL (Secure Sockets Layer) Protocol
    • TCP
    • TLS
    • UDP
Home
Deploying Avaya Aura® Device Services
TLS

TLS

Share this page

  • On LinkedIn
  • On X
  • On Email

PDF Export Options

  • This Topic
  • Entire Document
Last Updated : Jun 10, 2026 |
Avaya Aura® Device Services
Deploying
10.2.x

Transport Layer Security

Send Feedback

Topic navigation

Previous Topic

TCP

Next Topic

UDP

In this article

STAY CONNECTED

Twitter Youtube Linkedin
Footer Icon
  • Sitemap
  • Terms of use
  • Privacy
  • Cookie Policy
  • Trademarks
  • Accessibility
© 2026 Avaya LLC