Import Trusted Certificate page field descriptions

Last Updated : Sep 16, 2020 |
Prolog information
Use the two Import Trusted Certificate pages to import a new certificate for:
  • Application server: These certificates allow Avaya Experience Portal to use a secure connection between the MPPs and the application server.
  • LDAP server: These certificates allow Avaya Experience Portal to use a secure connection between the Primary EPM server and the LDAP server.
  • SIP Connection: These certificates allow a secure connection between Avaya Experience Portal and the VoIP servers.
  • Speech server: These certificates are used by the MPP for communicating with the speech servers when using MRCP V2 TLS protocol.
  • User: These certificates are used by the EPM to perform certificate based authentication for the web users.
  • System Manager: These certificates allow the EPM to Single Sign-On with the System Manager.
  • CRL File: Certificate Revocation List (or CRL) is a list of digital certificates that have been revoked by the issuing certificate authority (CA) before their scheduled expiration date and should no longer be trusted. All the certificates in use are checked against the CRL to determine if a certificate has been revoked or not.

Import Trusted Certificate page (page 1 of 2)

Field
Description
Name
The name of this certificate on the Avaya Experience Portal system.
Once you click Continue, this name cannot be changed.
Type
The options are:
Location
The URL for the security certificate. The URL must be in the format https://<host><:port>/ where host is the fully qualified host address or ip address, and :port is an optional parameter that consists of a colon followed by the port number. If no port number is specified, Avaya Experience Portal uses 443 as the port number for retrieving the security certificate.
Once you click Continue, this path cannot be changed.
Important:
If you select Speech server in the Type field, ensure:
  • The MRCP v2/TLS connection requires certificates and only the Nuance speech server supports this connection. So you need to add details in this field only for the Nuance speech server.
  • The Nuance certificate must be formatted as a .pem file. The following 4 certificates must reside in a certificate folder in Nuance speech server; domain_cert_localdomain.pem and _cert.pem, domain_key_localdomain.pem and _key.pem files.
  • Select only the _cert.pem certificate.
If you select User in the Type field, ensure:
  • To include a whole chain of certificates.
  • The Client Authentication (clientAuth) is specified If the Extended Key Usage is included in the X509 V3 extension of the certificate.
Continue
Submits the location to Avaya Experience Portal for verification.
Avaya Experience Portal downloads the SSL (Secure Sockets Layer) certificate from the designated location. If the SSL certificate fails to download, Avaya Experience Portal prompts you to correct the Location field entry and try again.
When the SSL certificate downloads successfully, Avaya Experience Portal displays the second Import Trusted Certificate page.

Import Trusted Certificate page (page 2 of 2)

The fields on this page are presented for confirmation purposes only. If you want to make any changes, you need to cancel this submission and repeat the process from the beginning.
Field
Description
Name
The name of this certificate on the Avaya Experience Portal system.
Type
The options are:
Location
The fully-qualified pathname of the security certificate.
Display text box
The text of the security certificate.
Save
Installs the displayed certificate on the EPM.