• If the SAN field is present in the certificate, following are the attributes specific to the
connection type:
For SIP-TLS connection
- With valid SIP URIs
• SIP URI attribute should have SIP domain name as value.
• IP attribute must have the IP address of LAN as value.
- Without valid SIP URIs
• DNS attribute with SIP domain as value.
• IP attribute with IP address of LAN as value.
For HTTP-TLS connection
- Provisioning phone with only IP address
• In the
SAN
field, IP attribute with IP of HTTPS server as value.
- Provisioning phone with FQDN of HTTPS server
• In the
SAN
field, IP attribute with the IP address of HTTPS server as value.
• DNS attribute with FQDN of HTTPS server as value.
Note:
While provisioning the phone with FQDN of HTTPS server, you need two attributes in the
SAN
field:
• DNS attribute with FQDN
• IP attribute IP address
Trusted certificates
Trusted certificates are root certificates of the certificate authority that issued the server or client
identity certificates in use. These certificates are installed on the phones through the HTTP server
and are used to validate server certificates during a TLS session.
System Manager includes EJBCA, an open source PKI Certificate Authority, that can be used to
issue and manage client and server certificates.
OCSP trust certificates
On Line Certificate Status Protocol (OCSP) trust certificates are installed when the trusted
certificates are already installed. OCSP trust certificates are also root (or intermediate) certificates
that are downloaded from the file server. OCSP is a protocol that is used for obtaining the revocation
status of an X.509 digital certificate. A new trust store is created to store OCSP trust certificates on
the phone.
Certificate management
September 2017
Installing and Administering Avaya J129 IP Phone
55