Signing certificates with the System Manager CA
Procedure
1. Log in to the System Manager web administration portal.
2. Navigate to
Security
>
Certificates
>
Authority
.
3. Ensure that the certificate profile is set as follows:
a.
Key Usage Extension
set to Digital Signature and Key Encipherment.
b.
Extended Key Usage
: set to Server Authentication and Client Authentication.
4. If you do not have an end entity, do the following:
a. Navigate to
Add End Entity
.
b. Provide a user name and password for the new entity.
The user name and password are required for issuing the certificate.
c. Continue performing the procedure from step 6.
5. If you already configured an end entity, do the following:
a. Navigate to
Search End Entity
.
b. Enter the user name that you provided when creating the entity and then click
Edit
End Entity
.
c. In
Status
, select
New
and enter the password.
d. Continue performing the procedure from the following step.
6. Configure the end entity fields as follows:
a.
Subject DN > CN
: FQDN of the server interface that provides TLS support.
b.
Subject Alternative Name
: For
DNS name
, enter the FQDN of the server interface
that provides TLS support, and for
IP Address
, enter the UP address of the IP
requiring TLS support.
c.
Certificate Profile
: Enter
ID_CLIENT_SERVER
with relevant key features.
d.
CA
: Enter
tmdefaultca
.
e.
Token
: Select
User Generated
.
7. Click
Add
if you are configuring a new entity or
Save
if you are configuring the existing
entity.
8. Navigate to
Public Web
>
Enroll
.
9. Click
Create Certificate from CSR
.
10. Enter the user name and password that you used when creating the end entity.
11. Open the CSR request file in the
CSR
format in a text editor and copy its content into a text
box on the page.
Certificate setup
October 2018
Deploying the Avaya Aura
®
Web Gateway
137