-
Check the setting .
-
Enter the Machine IP. This is used to create the file name, but not the certificate itself; an IPv4 address of that device should be entered.
-
Enter the Password. This is used to secure the identity certificate file and must conform to the complexity requirements.
-
-
Enter any subject alternative names.
-
Enter the number of days the certificate will be valid for. The start date/time will be the current UTC time of the server. The end date/time will be start time + number of days. Identity certificates should not be valid for more than three years (1095 days). The longer the period, the greater the risk of certificate compromise.
-
Enter the Public Key Algorithm. This should be RSA-2048 for all IP Office devices. RSA-1024 should only be used for legacy systems that cannot support RSA-2048.
-
Enter the Secure Hash Algorithm. This should be SHA-256 for all IP Office devices. SHA-1 should only be used for legacy systems that cannot support SHA-256.
-
Check the settings and then click Generate. This will cause the server to generate a PKCS#12 file containing the identity certificate, private key and signing certificate. The file is secured by the password entered and will be requested every time the file is opened.
-
A popup will prompt to save the file. Save the file to the local machine. Once the popup is close, the file will be deleted on the CA server.
-