The Primary Server CA should be used for Server Edition deployments. The Linux Application Server for non-Server Edition deployments. The same CA must be used for all systems in a deployment.
Enable the setting Platform ViewSettingsGeneralCertificatesRenew automatically on the Primary/Linux Application Server.
For every device (server, IP500 V2 and so on) use the CA to create a unique ID certificate for each with the correct name content and save to a local directory. The name fields of the certificate are important for correct interoperation with clients; see Certificate Name Content for more information. See Using the IP Office Certificate Authority.
Save the root CA certificate in both PEM and DER formats to a local directory using the IP Office Web Manager setting Platform ViewSettingsGeneralCertificatesCA CertificateDownload (PEM-Encoded) and Download (DER-Encoded).
Use IP Office Web Manager or IP Office Manager to save the CA certificate in each TCS.
Use IP Office Web Manager or IP Office Manager to save the ID certificate on the relevant IP Office server. See Update Certificates.
If SIP or H.323 phones are using HTTPS for provisioning or TLS for signaling, the IP Office root CA certificate must be present on each phone. See VoIP Security.
Distribute the root CA certificate to all clients and browsers. The mechanisms vary and some require PEM format, some require DER. See the relevant client and browser documentation.
Verify that the correct ID certificate has been applied on each device using a browser or other diagnostic tool.
Enable certificate checking in the IP Office security settings and IP Office lines.
Verify using SE Manager that all IP Office systems are online with no alarms.
Enable secure connections for clients.
Verify each client can connect successfully.
Ensure all ID certificate files are stored securely.
Once all checks have been carried out, a configuration backup should be taken.