Update Certificates

Last Updated : Apr 17, 2024 |

Procedure

  1. It is essential to understand the information and recommendations of Certificates and Trust to determine the certificate and trust requirements of the system prior to installation.
  2. If required, administer a new platform identity certificate:
    1. The new identity certificate should be in a 'p12' or 'pfx' file.
    2. Ideally, all certificates used to sign the new identity certificate should be in the same file.
    3. If the signing certificates are in separate files, use IP Office Manager security System > Certificates > Trusted Certificate Store > Add to upload each one.
    4. Activate the IP Office Manager security setting System > Certificates > Identity Certificate > Offer ID Certificate Chain.
    5. Use IP Office Manager security setting System > Certificates > Identity Certificate > Set to upload the identity certificate file.
    6. The identity certificate will be automatically propagated to all TLS/HTTPS interfaces of the server, any signing certificates will be placed in the Trusted Certificate Store (TCS).
    7. If a separate telephony identity certificate is required, it should be administered using IP Office Manager security settings.
    8. The default certificates trusted by IP Office should be removed if not required. This is achieved by placing a copy of the certificate in the system/primary/certificates/tcs/delete directory using the IP Office Manager or IP Office Web Manager's File Manager.
  3. Any default certificates to be trusted by IP Office should be added to the system/primary/certificates/tcs/add directory. See Default Trusted Certificates for more information and how to create the certificate files.
  4. If there is a change to the server's LAN IP address, SIP domain or FQDN, the Identity certificate will require regeneration. An IP500 V2, Secondary or Linux Expansion Server will always require manual regeneration. A Primary or Linux Application Server will be automatic if the IP Office Web Manager menu Platform View > Settings > General > Certificates > Renew automatically setting is active (default).
  5. After ensuring that all other IP Office components' identity certificates are correctly configured, set the received certificate check levels using the settings:
    • System > Certificates > Received Certificate Checks (Management Interfaces)

    • System > Certificates > Received Certificate Checks (Telephony Endpoints)