Configuring CRL download on primary and secondary System Manager server

Last Updated : Sep 21, 2023 |

About this task

This topic provides information about downloading and configuring the Certificate Revocation List (CRL) on the primary and secondary System Manager server.

Procedure

  1. Go to the login page of the primary System Manager server.
  2. Copy the CRL URL of the browser certificate.
  3. Replace the Virtual Fully Qualified Domain Name (VFQDN) in the CRL with the IP address of the primary System Manager server.

    Example:

    If the CRL URL in the certificate is:

    http://<vFQDN>/ejbca/publicweb/webdist/certdist?cmd=crl&issuer=CN=System%20Manager%20CA,OU=MGMT,O=AVAYA

    the new CRL for the certificate will be:

    http://<ip-address>/ejbca/publicweb/webdist/certdist?cmd=crl&issuer=CN=System%20Manager%20CA,OU=MGMT,O=AVAYA

    where, <vFQDN> and <ip-address> are the respective vFQDN and IP address.

    Note:

    This step is not required if a third-party certificate is installed on System Manager servers.

  4. Log on to the secondary System Manager web console.
  5. Click Home > Services > Security.

    The Security tab is displayed with its menu on the left panel.

  6. From the menu, click Configuration > CRL Download.

    The CRL Download Configuration page is displayed.

  7. Click Add.

    The Schedule CRL Download page is displayed.

  8. In Job Details section, type job name in the Job Name field.
  9. In Job Frequency section, set the frequency and recurrence to schedule the job after CRL addition.
    Note:

    For more information about field descriptions, see Administering Avaya Aura® System Manager

  10. Copy the new CRL URL from Notepad and paste it in the Configure CRL Distribution Point section, CRL Distribution Point field.

    Example:

    http://<ip-address>/ejbca/publicweb/webdist/certdist?cmd=crl&issuer=CN=System%20Manager%20CA,OU=MGMT,O=AVAYA

  11. Click Add and Commit to save the configuration.
    Note:

    The CRL Download Configuration page displays the job run status. Ensure that the job is completed successfully.