john3voltas
Technical User
Hello there.
Since my latest odyssey with expired self-signed certificates, I started investing more time in trying to understand the security section of IPO systems and also the nature of the Server Edition expansions systems. Meaning, I've been trying to understand what exactly is shared between the primary server and the secondary and expansion systems.
As I understand, we can synchronize service users and system passwords, single sign-on (Avaya Cloud), APNS (Apple Push Notification) and APNP (Avaya Spaces). in the WebManagement :7070 address.
From what I could gather, the sync for service users and their passwords is just that. User/Password combo. There is no sync of their rights groups and permissions.
On the other hand, the certificates.
As far as I could tell, the Identity and CA certificates are not shared between the server and the expansion systems.
My doubts:
- isn't this a Frankenstein what Avaya made with the Integrated Management of Server Edition?
- are we supposed to synchronize rights groups and permissions by hand? Is that what you guys do?
- since the Certs are different, should a phone loose connection with the Primary server and choose the secondary server or an expansion server to register, how will it validate the identity certificate?
My head is hurting lol
Since my latest odyssey with expired self-signed certificates, I started investing more time in trying to understand the security section of IPO systems and also the nature of the Server Edition expansions systems. Meaning, I've been trying to understand what exactly is shared between the primary server and the secondary and expansion systems.
As I understand, we can synchronize service users and system passwords, single sign-on (Avaya Cloud), APNS (Apple Push Notification) and APNP (Avaya Spaces). in the WebManagement :7070 address.
From what I could gather, the sync for service users and their passwords is just that. User/Password combo. There is no sync of their rights groups and permissions.
On the other hand, the certificates.
As far as I could tell, the Identity and CA certificates are not shared between the server and the expansion systems.
My doubts:
- isn't this a Frankenstein what Avaya made with the Integrated Management of Server Edition?
- are we supposed to synchronize rights groups and permissions by hand? Is that what you guys do?
- since the Certs are different, should a phone loose connection with the Primary server and choose the secondary server or an expansion server to register, how will it validate the identity certificate?
My head is hurting lol