Configuring WebLM, EASG, and the encryption passphrases

Last Updated : Apr 14, 2026 |
Prolog information
When you execute the cmssvc command for the first time after deploying an OVA, the system does not display the normal CMS Services menu. Instead, the system automatically prompts you to set up the following features:
  • WebLM
  • Enhanced Access Security Gateway (EASG)
  • Encryption passphrases
For WebLM licensing, you have 30 days to provide a valid host name to a WebLM Release 8.0 or later server where the CMS license is installed. If you cannot provide a valid host name, CMS enters the License Error mode for 30 days. After 30 days, CMS enters the License Restricted mode.
The Enhanced Access Security Gateway (EASG) package is integrated into CMS and provides secure authentication and auditing for all remote access into the maintenance ports.
EASG authentication is based on a challenge/response algorithm using a token-based private key-pair cryptographic authentication scheme. Secure auditing is also provided. Logs are available that include information such as successful log on, failed log on, errors, and exceptions.
EASG allows Avaya to control Avaya service engineer privileges when accessing customer products. EASG controls permission levels, such as init, inads, and craft, used by the service engineers.
CMS automatically encrypts the data partitions on the storage disk drive during an OVA deployment. Encryption is not optional — the data partitions on the storage disk drive are always encrypted. A newly-deployed or upgraded system is assigned two default encryption passphrases. You can choose from either of the following default encryption passphrases:
  • cmsdefault
  • cms190941
The customer must decide whether they will require an encryption passphrase to be entered on the console after the system has shut down and rebooted. This includes shutdowns for administrative or maintenance procedures such as turning FIPS on and off, CMSADM restore, LAN restore, RPM update, software upgrades, and regular maintenance reboots as recommended by Avaya. It also includes unplanned shutdowns such as a system crash.
Before you begin
Confirm that a valid CMS license has been obtained and installed on the WebLM server used with your deployment. This can be a standalone WebLM server or a System Manager server. When you install a license on the WebLM server, you must map the license by giving it a license ID. This license ID can be any value. For more information, see Standalone WebLM documentation or System Manager WebLM documentation.
Consult with the customer to find out whether they want to require an encryption passphrase after a shutdown and reboot. The customer can always change this decision.
  1. Log on as root to the CMS server.
    ADDITIONAL INFORMATION:
    Important:
    You cannot directly log on as root from a remote connection. You must log on using an administered CMS user ID, then use su - root to log on with root privileges.
  2. Enter:
    ADDITIONAL INFORMATION:
    cmssvc
    STEP RESULT:
    The system displays the following message:
    cmssvc: Warning IDS off-line. It will take approx 45 seconds to
    start cmssvc. IDS can be turned on with the run_ids command on
    the cmssvc menu. 
    You are required to set the WebLM server before proceeding.

    Please enter the hostname for the WebLM license server.
    If you do not have a WebLM license server, enter <CR>:
  3. Enter the host name or IP address of the WebLM server where the CMS license is installed.
  4. Press Enter.
    STEP RESULT:
    If you entered the correct WebLM server host name or IP address, the system displays the following message:
    Please enter the CMS server license ID: (default: <LicenseID>)
    Note:
    If you entered an incorrect WebLM server host name or IP address, the system displays the following message:
    Cannot connect to host: <HostName>

    Do you want to enter another hostname? (y/n):
    Enter y and enter the correct WebLM server host name.
  5. Enter the CMS server license ID. This is an ID created when the license was installed on the WebLM server.
  6. Press Enter.
    STEP RESULT:
    The system displays the following message:
    Web hostname is now authorized as https://<Host_Name or IP_Address>:<Port_Number>/WebLM/LicenseServer.

        EASG User Access

                By enabling Avaya Logins you are granting Avaya access to 
                your system.  This is necessary to maximize the performance 
                and value of your Avaya support entitlements, allowing Avaya 
                to resolve product issues in a timely manner.

                In addition to enabling the Avaya Logins, this product should 
                be registered with Avaya and technically onboarded for remote 
                connectivity and alarming. Please see the Avaya support site 
                (support.avaya.com/registration) for additional information for 
                registering products and establishing remote access and alarming.

    Would you like to enable Avaya EASG? (Recommended)
    [yes/no]:
  7. Do one of the following steps:
    • Enter yes to enable EASG. This is the recommended setting. The customer can always disable EASG if required.
    • Enter no to keep EASG in the disabled state.
      Note:
      If you do not enable EASG now, you can enable it later using the cmssvc command.
    STEP RESULT: Avaya EASG is now enabled

    Disk encryption is implemented on all CMS data partitions.

    Select one of the following:
      1) Require the encryption passphrase to be manually entered on the system
         console whenever the system is rebooted
      2) Enable auto-unlocking to allow the system to use a CMS generated local 
         key file to start up unattended without needing to enter the encryption 
         passphrase
    Enter choice (1-2):
  8. Select one of the following options based on what the customer wants:
    • Select 1 if the customer wants to require an encryption passphrase after a shutdown and reboot.
    • Select 2 if the customer wants to allow the system to use a CMS-generated local key file to boot up without an encryption passphrase. During deployment, you should select option 2 since you might be rebooting the system a few times. The customer can change this after you have turned the system over to the customer.