Configuring X.509 certificate authentication

Last Updated : Jan 13, 2020 |

About this task

Note:

X.509 certificate authentication has the following limitations:

  • Certificate verification will fail unless the root CA and all intermediate CAs are added as trust anchors and/or intermediates on the Avaya SBC system regardless of whether the client sends the full trust chain.

  • Online Certificate Status Protocol (OCSP) checking is currently not supported.

  • Certificate Revocation List (CRL) Distribution Point checking is not supported.

Procedure

  1. Log on to the EMS web interface with administrator credentials.
  2. From the Device drop-down list, select EMS.
  3. Navigate to System Administration > AAA.
  4. Select the X.509 tab.
  5. Administer the X.509 certificate authentication with the options described in X.509 certificate authentication field descriptions.
  6. Click Save.

    The system saves the X.509 certificate authentication configuration.