Approach 2: PKI Trust domain based on Primary or Linux Application Server Intermediate CA

Last Updated : Apr 14, 2022 |
Prolog information
This option allows identity certificates to be generated on the Primary or Linux Application Server using an intermediate CA certificate obtained from an external Certificate Authority.
Potential advantages for intermediate CA certificate on the Primary/Linux Application Server:
  • Generated ID certificates are part of a wider trust
  • Control of the CA is internal.
  • ID certificate content format compatible with other Avaya components.
  • ID certificates with private domains and address ranges IP addresses can be created
  • The root CA certificate is (typically) trusted by 3rd parties and therefore does not need to be distributed.
Potential disadvantages include:
  • Cost - if using a commercial provider. Signing certificates are typically more expensive.
  • The certificate policy is subject to commercial considerations.
  • Many public certificate authorities will not issue intermediate CA certificates for private domains or IP address ranges.
  • The root CA certificate is untrusted by IP Office components and therefore needs to be distributed.
  • The certificate creation and distribution process is manual.
  • All clients need to support certificate chains in the TLS exchange; if not the intermediate CA certificate needs to be distributed.