Howto:Setup new push.innovaphone.com certificate: Difference between revisions

From innovaphone wiki
Jump to navigation Jump to search
Line 12: Line 12:
To ensure that Push will work for your customers after 01.09.2025, verify that the CA certificate <code>innovaphone Device Certification Authority 2</code> or the single certificate <code>push.innovaphone.com</code> is in the trust list of the respective PBXes.
To ensure that Push will work for your customers after 01.09.2025, verify that the CA certificate <code>innovaphone Device Certification Authority 2</code> or the single certificate <code>push.innovaphone.com</code> is in the trust list of the respective PBXes.
This certificate is only relevant on PBXes with a Push Object.  
This certificate is only relevant on PBXes with a Push Object.  
During the transition period up to and including 02.09.2025, both <code>*.innovaphone.com</code> one of the above named certificates are required.
During the transition period up to and including 02.09.2025, both <code>*.innovaphone.com</code> and one of the above named certificates are required in the trustlist.
 
For this, make sure that your setup is compatible to the [[Reference15r1:Concept App Service Devices#Certificates configuration|Devices - certificate trustlist concept]]. Then the certificate will be installed automatically.


===Resolution===
===Resolution===
Line 24: Line 22:
1. The certificate can be added manually on the PBX. It can be downloaded [https://download.innovaphone.com/certificates/innovaphone.pem here] and then be uploaded on the PBX under [[Reference15r1:General/Certificates|General/Certificates/Trust list]].  
1. The certificate can be added manually on the PBX. It can be downloaded [https://download.innovaphone.com/certificates/innovaphone.pem here] and then be uploaded on the PBX under [[Reference15r1:General/Certificates|General/Certificates/Trust list]].  


2. The new certificate can be added via commands (which can be sent using an update server or the [[Reference15r1:Concept_App_Service_Devices#Expert configuration| Expert configuration]] in ''Devices''). This needs a reboot of the device.  
2. The new certificate can be added via commands (which can be sent using an update server or the [[Reference15r1:Concept App Service Devices#Expert configuration| Expert configuration]] in ''Devices''). This needs a reboot of the device.  
Save the new certificate in the trust list:
Save the new certificate in the trust list:
  !vars create X509/TRUSTED pba 6239515b5008c67cbcd66f07a539f4107dc48348e69a0382aabe640a5a2b62b5b63079bcb9a826819bb71518c8cd9d5e365f6a1059d6b6854781e61239108fb0eacacba6166843ed1973e0b268c3b5ba44b8efcd243032999af9a7f8cd375915b854ceca843a340f60be747a66200abb9eddbfd5ba204a1e1dabbc6fceb61e05243e4f191e7ff20bcc6cb29852f568437eeeb51d7657da1f9b245441a72dd42b4e8e80f916154b009c564ba3b79c9e20f40bef8cd84317bd0a9ceccd3ce312ec5fd350f9d366dd5f6f09119669383efbf580cdca3f7524da153984cec62f14e372d8324256302b7e567c0ca051d4c30023ee5bbd241ddfd6e75711a6018d12d7
  !vars create X509/TRUSTED pba 6239515b5008c67cbcd66f07a539f4107dc48348e69a0382aabe640a5a2b62b5b63079bcb9a826819bb71518c8cd9d5e365f6a1059d6b6854781e61239108fb0eacacba6166843ed1973e0b268c3b5ba44b8efcd243032999af9a7f8cd375915b854ceca843a340f60be747a66200abb9eddbfd5ba204a1e1dabbc6fceb61e05243e4f191e7ff20bcc6cb29852f568437eeeb51d7657da1f9b245441a72dd42b4e8e80f916154b009c564ba3b79c9e20f40bef8cd84317bd0a9ceccd3ce312ec5fd350f9d366dd5f6f09119669383efbf580cdca3f7524da153984cec62f14e372d8324256302b7e567c0ca051d4c30023ee5bbd241ddfd6e75711a6018d12d7


[[Category:Howto|{{PAGENAME}}]]
[[Category:Howto|{{PAGENAME}}]]

Revision as of 13:31, 21 May 2025

FIXME: Draft, not finished yet!

Applies To

This information applies to

  • All innovaphone PBXs from V12 which use the Push service

More Information

Problem Details

On 01.09.2025 we will change the used certificate in the Push infrastructure. Today we use *.innovaphone.com which will expire every year, and you have to update it every year. This is used in the PBX trust list to establish an encrypted connection between your PBX and the innovaphone push service. To simplify this in the future, we will change the certificate once again to a certificate which is signed by our innovaphone Device Certification Authority 2.

To ensure that Push will work for your customers after 01.09.2025, verify that the CA certificate innovaphone Device Certification Authority 2 or the single certificate push.innovaphone.com is in the trust list of the respective PBXes. This certificate is only relevant on PBXes with a Push Object. During the transition period up to and including 02.09.2025, both *.innovaphone.com and one of the above named certificates are required in the trustlist.

Resolution

Use the Devices - certificate trustlist concept and the certificate will be installed automatically.

manually

If you cannot do this and want to do it manually, you can use one of these ways:

1. The certificate can be added manually on the PBX. It can be downloaded here and then be uploaded on the PBX under General/Certificates/Trust list.

2. The new certificate can be added via commands (which can be sent using an update server or the Expert configuration in Devices). This needs a reboot of the device. Save the new certificate in the trust list:

!vars create X509/TRUSTED pba 6239515b5008c67cbcd66f07a539f4107dc48348e69a0382aabe640a5a2b62b5b63079bcb9a826819bb71518c8cd9d5e365f6a1059d6b6854781e61239108fb0eacacba6166843ed1973e0b268c3b5ba44b8efcd243032999af9a7f8cd375915b854ceca843a340f60be747a66200abb9eddbfd5ba204a1e1dabbc6fceb61e05243e4f191e7ff20bcc6cb29852f568437eeeb51d7657da1f9b245441a72dd42b4e8e80f916154b009c564ba3b79c9e20f40bef8cd84317bd0a9ceccd3ce312ec5fd350f9d366dd5f6f09119669383efbf580cdca3f7524da153984cec62f14e372d8324256302b7e567c0ca051d4c30023ee5bbd241ddfd6e75711a6018d12d7