Creating the common server certificate

Last Updated : Sep 05, 2020 |

About this task

Use this procedure to create the common server certificate that you require while creating a server profile for Avaya Aura® Session Border Controller.

Procedure

  1. Create an end entity by performing the following steps:
    1. On the System Manager web console, click Services > Security > Certificates > Authority.
    2. In the navigation pane, in the RA Functions section, click Add End Entity.
    3. In the End Entity Profile field, select INBOUND_OUTBOUND_TLS.
    4. In the Username field, enter a user name.

      For example, SBCEXT.

    5. In the Password (or Enrollment Code) field, enter a password.

      Ensure that you make a note of the user name and password. The user name and password are required when creating a certificate for this server.

    6. In the Confirm Password field, re-enter the password.
    7. In the CN, Common name field, enter the FQDN of Session Border Controller.

      For example, Subject: CN=primary_sbc.apac.avaya.com, CN=secondary_sbc.apac.avaya.com, OU=SDP, O=AVAYA, C=US

    8. In the first DNS Name field, enter the enter the FQDN for Avaya Aura® Web Gateway of the cluster.

      For example, DNS1: aawg.apac.avaya.com.

    9. In the second DNS Name field, enter the domain name of the second node of the cluster.

      For example, DNS2: apac.avaya.com

    10. In the IP Address field, enter the IP address of the external interface.
    11. In the Token field, select P12 file.
    12. Click Add.
  2. Create a keystore by performing the following steps:
    1. On the System Manager web console, click Services > Security > Certificates > Authority.
    2. In the navigation pane, click Public Web.
    3. On the EJBCA welcome page, in the navigation pane, click Create Keystore.
    4. On the Keystore Enrollment page, enter the user name and password that you specified while creating the end entity.
    5. Click OK.
    6. Select the Key Length as 2048 bits.
    7. Click Enroll.
    8. Save the certificate file.