The CA on the Primary or Linux Application Server is not used.
Enable the setting Platform ViewSettingsGeneralCertificatesRenew automatically.
Select an appropriate Certificate Authority that can fulfill the trust and certificate requirement of the deployment. For more information on external public authorities, see Certificate from External Certificate Authorities.
For every device (server, IP500 V2 and so on) request the CA to create a unique ID certificate for each with the correct name content and save to a local directory. The name fields of the certificate are important for correct interoperation with clients; see Certificate Name Content for more information.
For IP500 V2 devices, an external form based CSR must be used. For IP Office Linux devices, a PKCS#10 CSR can be created using the CLI. For more information on the CSR process, see Certificate Signing Requests.
Download the root and any intermediate CA certificate from the Certificate Authority in PEM and DER format to a local directory.
Use IP Office Web Manager or IP Office Manager to:
ADDITIONAL INFORMATION:
Save both the root and intermediate CA certificate in the TCS.
Activate the certificate chaining feature Offer ID Certificate Chain.
Use IP Office Web Manager or IP Office Manager to save the ID certificate on the relevant IP Office server. See Update Certificates.
Distribution of the root CA certificate to phones, clients and browsers is as per PKI Trust Domain based on Primary or Linux Application Server root CA section above.
Verification and enabling steps are as per PKI Trust Domain based on Primary or Linux Application Server root CA section above, with the note that many external CAs provide online verification tools.
Once all checks have been carried out, a configuration backup should be taken.