Provisioning server mutual authentication support

Last Updated : Aug 28, 2026 |
Prolog information
Use the Device Enrollment Services server to install a client identity certificate on the phone. The phone uses the identity certificate when connecting to a provisioning server that requires mutual TLS authentication.
During mutual TLS authentication, the phone validates the provisioning server certificate and presents an identity certificate to the provisioning server. To validate the certificate, the provisioning server must trust the root certificate authority (CA) certificate issuing the phone identity certificate.
You can configure the Device Enrollment Services server so that the phone requires an identity certificate for mutual authentication with the provisioning server. The phone accepts the certificate and then queries the Device Enrollment Services server for the provisioning server URL.
To use this functionality, you must install the Avaya Devices root certificate for issuing identity certificates on the provisioning server.
For more information on installing the Device Enrollment Services Hardware Security Modules (HSM) root certificate, see Avaya Device Enrollment Services documentation.