Installing certificates

Last Updated : Mar 18, 2020 |

About this task

Important:

For an HA pair, the certificate and key are uploaded to the primary device and synchronized to the secondary device. However, if you add a new certificate and key on the EMS, you must manually click Synchronize to HA Peer to so that the certificate and keys are synchronized onto the secondary device.

Procedure

  1. Log in to the EMS web interface with administrator credentials.
  2. From the Device menu, click the SBC name to administer.
  3. Navigate to TLS Management > Certificate.
  4. Click Generate CSR.
  5. Enter appropriate information in the Generate CSR screen, and click Generate CSR.

    If you have any other method available, you need not generate CSR using the Avaya SBC EMS web interface.

  6. Use the following settings if you want to generate CSR using alternate methods:
    • Certificate: keyUsage = keyEncipherment

    • Private Key: SHA256 with 2048–bit size

    These settings are generated automatically when you generate CSR using the Avaya SBC EMS web interface.

  7. If you generate CSR using the Avaya SBC EMS web interface, download the CSR to your computer.
  8. Send the CSR to the Certificate Authority (CA) for signing.

    The CA signs the CSR by using the methods that are acceptable at the site.

Next Steps

Upload the signed X.509 certificate, the key file, and the trust chain, if necessary, to the EMS through the EMS GUI.