Currently IP Office certificate support does not include the following:
You cannot configure mutual authentication for IP Office Linux-based applications, including Avaya one-X® Portal for IP Office and Voicemail Pro. They cannot check any received certificate against the TCS.
SIP clients certificates are not requested.
The received certificate tests of IP Office do not include revocation checks such as OCSP or CRLs.
No support for DSA or EC-DSA public key certificates, or RSA public keys above 4096 bits. Avaya recommends using RSA public keys of 2048 bits.
The IP500 V2 servers does not support the manual generation of a Certificate Signing Request (CSR) where the private key is retained within the server.
Use either a web form based request or a third-party tool to create a CSR. See Certificate Signing Requests for more information on how to generate a CSR for IP Office.