About Root-CA Certificates

Last Updated : Jun 04, 2021 |

One or more Root CA certificates must be installed for each entity that the gateway communicates with using TLS.

  • The signing authority for Avaya Aura® Communication Manager may be different from the signing authority for the gateway.

  • In complex security topologies, there may be multiple Communication Managers, each having a different signing authority. Multiple Root-CA certificates must be installed if the media gateway has these in its MGC list.

  • This feature supports two applications in which Root-CA certificates may be used, that is h248reg and sla.

    • h248reg designates that the certificate will be used for H.248 link establishment with Communication Manager.

    • sla designates that the certificate will be used for link establishment to an SLA Monitor server for diagnostic purpose.

    • syslog designates that the certificate will be used for link establishment to a remote syslog server.

    • web designates that the certificate will be used for link establishment to a remote HTTPS server.

  • The copy mechanism can be either SCP (secure copy) for download from a remote host site or USB for a download from USB memory drive. The user will be prompted for a login/password on the remote host system when scp is used to install a certificate.