This option allows identity certificates to be obtained direct from an external Certificate Authority using a manual process.
Potential advantages for identity certificates from an external CA:
-
Useful for small deployments when no Primary or Linux Application Server exists.
-
Generated ID certificates are part of wider trust domain.
-
The root CA certificate is (typically) trusted by 3rd parties and therefore does not need to be distributed.
Potential disadvantages include:
-
Public certificate authorities will not issue certificates for private domains or IP address ranges.
-
Cost - if using a commercial provider.
-
Control of the CA is external.
-
The certificate policy is subject to commercial considerations. ID certificate content format may not be compatible with Avaya components.
-
The root CA certificate is untrusted by IP Office components and therefore needs to be distributed.
-
The certificate creation and distribution process is manual.