User's Client Software and Platform requirements for secure connections

Last Updated : Sep 26, 2020 |

Avaya Oceana® and Avaya Analytics™ users require client PCs and browser clients to access the contact center functionality provided by the solution. The software client is Avaya Workspaces which is a browser-based client, with no client software download required to the user's PC.

When the user is configured as an Avaya Oceana® or Avaya Analytics™ user, with the correct permissions, the user can login and activate to perform the contact center functions and reporting tasks. An important aspect for all users, on premise in the enterprise or remote on the internet, is the ability for secure communications between the user's client PC and software, and the solution components. This can be achieved by the use of security certificates specifically importing the CA or root cert into the trust store of the user’s PC and browser.

Transport Layer Security (TLS) is an industry wide standard for encrypting data between clients (browsers) and servers (applications). This is achieved through the use of a security certificate that is trusted between the client and the server application. Key to this trust is the issuer or signing authority of the certificate more commonly referred to as the CA. The CA must be trusted by the client browser and in order to achieve this trust, the CA root certificate must be installed in the browser’s trust store.

The root certificates of a known external Certificate Authority are installed and trusted by default in most browsers. However, if for example, you are using Avaya Aura® System Manager or a private Enterprise CA, then the root or CA certificate cannot be automatically installed in the user’s browser.

Many enterprises have the ability for IT tools, policies and applications to push out the required root or CA certificates to all users' browsers or client PC trust stores. After the certificates are installed, the users are able to securely connect to their required applications without further action. However, if the certificate is not in place, the user has to accept the risk to connect insecurely to the server applications.

Clicking on the Proceed to an application means the user is bypassing the warning and setting up an insecure connection from their browser to the end application server. The user has to do this every time they connect to a particular backend server that has a CA issued SSL certificate.