Configuring token-based access between Control Manager and Avaya Oceana®, Avaya Analytics™, or Avaya Workspaces for Call Center Elite

Last Updated : Feb 23, 2022 |
Complete the procedures in this section to configure token-based access between Control Manager and Avaya Oceana®, Avaya Analytics™, or Avaya Workspaces for Call Center Elite.
Prolog information
Token enforcement requires that the REST API client first requests a token from the Avaya Breeze® platform Authorization Service. The client sends a digitally-signed token request to the service with a list of objects to access. If the Authorization Service recognizes the client and grants access to the resource, the service returns a signed token. The client uses this token in subsequent calls to the target REST service. The service endpoint checks the validity of the token on each request and processes a request only if the token is valid.
For token-based access to work, perform the following procedures:
  • Create a trust between Control Manager and Authorization service by:
    1. Obtaining the System Manager root certificate.
    2. Installing the root certificates from the Avaya Breeze® platform cluster to host the Authorization service as a trusted root certificate authority on the Control Manager application server.
    3. Updating the Avaya Oceana® UCA server URL.
  • Export the Control Manager public certificate.
  • Install the Control Manager public certificates in the Authorization clients list so that the Authorization service recognizes token requests from the Control Manager server.
  • Assign Grants to the Control Manager client to define the list of resources that can access the Control Manager server.
  • Enable token-based access in Control Manager.
  • Configure the Avaya Breeze® platform assigned Client ID for Control Manager in Control Manager.
Note:
For the Multiple HA setup, you must repeat the same procedure on each application server.
Before you begin
  • Ensure that you installed the signed certificates on the Control Manager deployment. For information about certificate installation, see Installing Avaya Control Manager and Upgrading Avaya Control Manager guides.
  • On the System Manager web console, click ServicesInventoryManage Elements and identify the root CA that was used to sign the certificate for one of the nodes in the Avaya Breeze® platform cluster that hosts the Authorization service.