Approach 2: PKI Trust Domain based on Primary or Linux Application Server Intermediate CA

Last Updated : Apr 20, 2022 |
Prolog information
  1. The Primary Server CA should be used for Server Edition deployments. The Linux Application Server for non-Server Edition deployments. The same CA must be used for all systems in a deployment.
  2. Enable the setting Platform ViewSettingsGeneralCertificatesRenew automatically on the Primary/Linux Application Server.
  3. Select an appropriate Certificate Authority that can fulfill the trust and certificate requirement of the deployment. For more information on external public authorities, see Certificate from External Certificate Authorities.
  4. Request an Intermediate CA certificate/private key pair from a trusted Certificate Authority in PCKS#12 format. An intermediate CA certificate differs in content to a root CA or a device identity certificate.
  5. Download the root CA certificate (and any further intermediate CA certificates) from the Certificate Authority in PEM and DER format to a local directory.
  6. Install Intermediate CA certificate the on the Primary or Linux Application Server. This can either be done during ignition, or post ignition via the IP Office Web Manager setting Platform ViewSettingsGeneralCertificatesCA CertificateImport.
  7. For every device (server, IP500 V2 and so on) use the CA to create a unique ID certificate for each with the correct name content and save to a local directory. The name fields of the certificate are important for correct interoperation with clients; see Certificate Name Content for more information. See Using the IP Office Certificate Authority.
  8. Save the intermediate CA certificate in both PEM and DER formats to a local directory using the IP Office Web Manager setting Platform ViewSettingsGeneralCertificatesCA CertificateDownload (PEM-Encoded) and Download (DER-Encoded)..
  9. Use IP Office Web Manager or IP Office Manager to:
    ADDITIONAL INFORMATION:
    • Save both the root and intermediate CA certificate in the TCS, then
    • Activate the certificate chaining feature Offer ID Certificate Chain.
  10. Use IP Office Web Manager or IP Office Manager to save the ID certificate on the relevant IP Office server. See Update Certificates.
  11. Distribution of the root CA certificate to phones, clients and browsers is as per PKI Trust Domain based on Primary or Linux Application Server root CA section above.
  12. Verification and enabling steps are as per PKI Trust Domain based on Primary or Linux Application Server root CA section above, with the note that many external CAs provide online verification tools.
  13. Once all checks have been carried out, a configuration backup should be taken.