Avaya Support Forums  

Go Back   Avaya Support Forums > IP Telephony and Convergence

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-19-2018, 08:29 AM
thargi thargi is offline
Member
 
Join Date: Feb 2017
Posts: 9
thargi has 10 reputation points
Default Avaya Utility Server - IP Phone Certificate(s)

CM/SMGR/ASM/Utility Server 7.1

Two questions:
What specific certificate(s) should be used/generated for IP phones – 96xx, Vantage, H175, etc?
And, how are certificates (certs) supposed to be uploaded to Avaya Utility Server (AUS)?

I have a couple of certs that were generated from System Manager (SMGR). I attempted to upload them via the Upload Signed (CSR) Certificate and Upload Root Certificate links. However, when I did, it “broke” Utility Server – I was no longer able to get back into AUS. Avaya had to fix it. Avaya had the following to say about its fix:
[Avaya] found that the certificates are broken which eventually broke the connection with the http. If the certificate chain is broken for some reason, then Apache will not start and so it is tricky to see what is going on. However, there is a backup of the standard certificate stored on Utility Services. The active certificate chain is always Utility_Server.pem as stored in /etc/pki/tls. But the backup certificate is in the same directory and called MV_IPTel.pem. So, log on as root, copy the backup cert to Utility_Server.pem, and then restart Apache.
The problem with this is that customers do not have root access. Not a big deal; I can always have Avaya fix it under maintenance.

However, it is a big deal that I cannot upload a cert without breaking AUS.

I did try the Upload Files link, but that did nothing. I could not even find where the files went after being uploaded.

Any help would be appreciated.
Reply With Quote
  #2  
Old 09-19-2018, 10:13 AM
mlombardi1's Avatar
mlombardi1 mlombardi1 is offline
Legend
 
Join Date: Sep 2010
Location: New York
Posts: 516
mlombardi1 has 25 to 49 reputation pointsmlombardi1 has 25 to 49 reputation pointsmlombardi1 has 25 to 49 reputation points
Default

The "Upload CSR" and "Upload root cert" options are for changing the default certificate on the US itself used for HTTPS connections.

To upload a root certificate to be served to IP phones, use the "Upload custom phone file" option which places it into the /var/www/html/ directory.

The generic "Upload files" option places files into /tmp.

I agree that lacking root privilege on this product is a problem.
Reply With Quote
  #3  
Old 09-19-2018, 12:48 PM
thargi thargi is offline
Member
 
Join Date: Feb 2017
Posts: 9
thargi has 10 reputation points
Default

Quote:
Originally Posted by mlombardi1 View Post
The "Upload CSR" and "Upload root cert" options are for changing the default certificate on the US itself used for HTTPS connections.

To upload a root certificate to be served to IP phones, use the "Upload custom phone file" option which places it into the /var/www/html/ directory.

The generic "Upload files" option places files into /tmp.

I agree that lacking root privilege on this product is a problem.

Thank you for the response. I will give that a shot. I guess I thought that IP Phone Custom File Upload was just for .tar files (firmware files).

I wonder if I can ssh to the Utility Server via WinSCP and just move the files into that directory.
Reply With Quote
  #4  
Old 09-20-2018, 06:52 AM
thargi thargi is offline
Member
 
Join Date: Feb 2017
Posts: 9
thargi has 10 reputation points
Default

Quote:
Originally Posted by thargi View Post
Originally Posted by mlombardi1
The "Upload CSR" and "Upload root cert" options are for changing the default certificate on the US itself used for HTTPS connections.

To upload a root certificate to be served to IP phones, use the "Upload custom phone file" option which places it into the /var/www/html/ directory.

The generic "Upload files" option places files into /tmp.

I agree that lacking root privilege on this product is a problem.
Thank you for the response. I will give that a shot. I guess I thought that IP Phone Custom File Upload was just for .tar files (firmware files).

I wonder if I can ssh to the Utility Server via WinSCP and just move the files into that directory.
Well, that worked. And, I can also move the files via SSH.
Thanks again.
Reply With Quote
Reply

Tags
avaya, certificates, upload file, utility server

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 02:14 PM.

This Forum is provided solely for the use and convenience of Avaya customers and partners. Use of the Forum is subject to the Terms and Use and Privacy Statement found at www.avaya.com. No other use is permitted. The Forum including all content posted is “AS IS” and Avaya expressly disclaims all warranties and/or guarantees as to its accuracy, reliability, usefulness, quality or non-infringement of intellectual property. Avaya reserves the right to remove any content posted on the Forum at any time and for whatever reason.

Avaya will not be liable for any content posted on this Forum, including, without limitation, any errors or omissions or for any losses or damages of any kind incurred as a result of use or reliance on any content, regardless of its origin.

You expressly understand and agree that you assume all risks associated with use or reliance on this content.