A Public Key Infrastructure (PKI) identify certificate is used to establish a secure connection between the device and the provisioning server. The certificate is required when the provisioning server uses a secure HTTPS connection with mutual authentication. The device receives the certificate from Device Enrollment Services.
When you enable Avaya certificate generation, the device gets the identity certificate from the Avaya Devices Root Certification Authority (CA). If Avaya CA generates the identity certificate, you can configure a secure connection between the device and the provisioning server. After the identity certificate is generated, the device uses the new identity certificate. The link to the Avaya CA is https://des.avaya.com/downloads/DeviceEnrollmentServiceRootCA.pem.
For general information about enabling mutual authentication, see the following links: