Creating the common certificate

Last Updated : May 12, 2025 |
If your system uses authorization certificates created by a third-party certificate authority, you may reuse them. Alternatively, you can create authorization certificates using the same service. You can reuse the existing certificates if they are created with the FQDNs and IP addresses of every node in the cluster.
Important:
Authorization certificates are used only for internal communication. Therefore, you can use the System Manager-generated certificates. If you already have a valid pk12-format certificate file, you can skip these steps.
  1. Create an end entity: Log on to Avaya Aura® System Manager.
  2. On the System Manager web console, click ServicesSecurityCertificatesAuthority.
  3. In the navigation pane, in the RA Functions section, click Add End Entity.
  4. In the End Entity Profile field, select INBOUND_OUTBOUND_TLS.
  5. In the Username field, enter a user name.
  6. In the Password (or Enrollment Code) field, enter a password.
    ADDITIONAL INFORMATION:
    Ensure that you make a note of the user name and password. The user name and password are required when creating a certificate for this server.
  7. In the Confirm Password field, re-enter the password.
  8. In the CN, Common name field, enter the FQDN of the cluster1.
  9. In the Subject Alternative Name area, in the first DNS Name field, enter the FQDN of the Cluster1.
    • In the next DNS Name field, enter the Cluster 1 Node 1 Management FQDN.
    • In the next DNS Name field, enter the Cluster 1 Node 1 SIP FQDN.
    • In the next DNS Name field, enter the Cluster 1 Node 2 Management FQDN.
    • In the next DNS Name field, enter the Cluster 1 Node 2 SIP FQDN.
    • In the next DNS Name field, enter the Cluster 1 Node 3 Management FQDN.
    • In the next DNS Name field, enter the Cluster 1 Node 3 SIP FQDN.
    Note:
    In a large deployment with two clusters, please perform the same steps for the two Breeze nodes in Cluster 2.
  10. In the IP Address field, enter the IP address of the cluster.
  11. In the Token field, select P12 file.
  12. Click Add.
  13. Create a keystore: On the System Manager web console, click ServicesSecurityCertificatesAuthority.
  14. In the navigation pane, click Public Web.
  15. On the EJBCA welcome page, in the navigation pane, click Create Keystore.
  16. On the Keystore Enrollment page, enter the user name and password that you specified while creating the end entity.
  17. Click OK.
  18. Select the Key Length as 2048 bits.
  19. Click Enroll.
  20. Save the certificate file.