Howto:Setup new push.innovaphone.com certificate

From innovaphone wiki
Revision as of 07:34, 21 May 2025 by Slu (talk | contribs) (Created page with "{{FIXME|reason=Draft, not finished yet!}} ==Applies To== This information applies to * All innovaphone PBXs from V12 which use the Push service ==More Information== ===Problem Details=== On 01.09.2025 we will change the used certificate in the push infrastructure. Today we use <code>*.innovaphone.com</code> which will expire every year, and you have to update it every year. This is used in the PBX trust list to establish an encrypted connection between your PBX and th...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
FIXME: Draft, not finished yet!

Applies To

This information applies to

  • All innovaphone PBXs from V12 which use the Push service

More Information

Problem Details

On 01.09.2025 we will change the used certificate in the push infrastructure. Today we use *.innovaphone.com which will expire every year, and you have to update it every year. This is used in the PBX trust list to establish an encrypted connection between your PBX and the innovaphone push service. To simplify this in the future, we will change the certificate once again to a certificate which is signed by our innovaphone Device Certification Authority 2.

To ensure that Push will work for your customers after 01.09.2025, verify that the CA certificate innovaphone Device Certification Authority 2 or the single certificate push.innovaphone.com is in the trust list of the respective PBXes. This certificate is only relevant for gateways on which Push is running. During the transition period up to and including 03.09.2025, both *.innovaphone.com one of the above named certificates are required.

If you already trust our CA innovaphone Device Certification Authority 2, there is nothing to do for you.

If you use the Devices - certificate trustlist concept you are not affected, and the certificate will be installed automatically.

Resolution

Here are two ways to replace the certificate on all innovaphone devices.

1. The certificate can be added manually on the PBX. It can be downloaded here and then be uploaded on the PBX under General/Certificates/Trust list.

2. The new certificate can be added via commands (which can be sent using an update server or the Expert configuration in Devices). This needs a reboot of the device. Save the new certificate in the trust list:

!vars create X509/TRUSTED pba 6239515b5008c67cbcd66f07a539f4107dc48348e69a0382aabe640a5a2b62b5b63079bcb9a826819bb71518c8cd9d5e365f6a1059d6b6854781e61239108fb0eacacba6166843ed1973e0b268c3b5ba44b8efcd243032999af9a7f8cd375915b854ceca843a340f60be747a66200abb9eddbfd5ba204a1e1dabbc6fceb61e05243e4f191e7ff20bcc6cb29852f568437eeeb51d7657da1f9b245441a72dd42b4e8e80f916154b009c564ba3b79c9e20f40bef8cd84317bd0a9ceccd3ce312ec5fd350f9d366dd5f6f09119669383efbf580cdca3f7524da153984cec62f14e372d8324256302b7e567c0ca051d4c30023ee5bbd241ddfd6e75711a6018d12d7