- Contents
Using the Single Third-Party Certificate Mode for PureConnect IC 2022 R2
Third-party certificates can be used with all the below off-server components
1. CIC Server
2. Media Server
3. OSSM
4. Scheduled Reports
5. SIP Proxy
6. Interaction Recorder
7. RCS (Remote Content Server)
8. Dialer
9. Campaign Server
10. SIP Softphone
11. ICWS-based applications
12. IceLib-based applications
13. IPA (Interaction Process Automation)
14. CX Insights
15. Multisite (EMS Server)
16. Director
Note: Third Party certificate validation is not required for Schedule Reports as it uses the native Notifier connection between CIC and schedule report server and works on internal network TLS certificates and so the SQL DB is already secured. For “Director” the release testing was stopped because of no customers and due to the complexity of the test environment.
Interaction Center version 2018 R5 and later can operate on a Single Third-Party Certificate to run the PureConnect applications and associated subsystems. You may now store your Third Party Signed Certificates in the local Server’s “Windows Certificate Store” to minimize human certificate manipulation. The PureConnect Certificate Wizard can import those Third Party Signed Certificates from the local Windows Certificate Store and to encrypt the Certificates with a Master Key. Depending on your requirements, Master Key encryption may or may not be required. Check with the appropriate vulnerability security personal before determining your agency’s requirements.
You can generate a single server certificate through the Setup Assistant for the PureConnect IC Server or use the GenSSLCertsU Command Line tool for the other Off IC Server components such as the Media servers, RCS, and Off Host Session manager servers. This option forces all xIC subsystems to use the single server certificate and private key for all uses. While this option reduces the complexity of managing certificates and private keys, all xIC subsystems become insecure if the single server private key becomes compromised.
Please note that if you select to use the single server certificate option, you will not be able to generate new certificates and private keys, until you Re-run the Setup Assistant or the GenSSLCertsU tool and select a different certificate signing option.
For Third-Party Certificate deployments, you may need to create a Domain User account named “ICService” on the Customers Domain that we use to log on to and install or upgrade the PureConnect IC Server applications (we use this same account on other IC sub-system peripheral servers as well. This “ICService” account becomes the “Service” account that Windows uses to run PureConnect as a service. This “Service” account will have the required ACLs and permissions to encrypt and run PureConnect in the Master Key mode should you need this level of security. Note, only the “ICService” account will have the required permissions to enable and run PureConnect IC applications once you start using Third-Party certificates.
The “ICService” account can be named anything you want it to be named. Just be sure that this account is the account that you must use to log onto the PureConnect IC Server and install the PureConnect IC applications as a complete system.
For more information about using the GenSSLCertU tool, refer to the Generating Certificates Manually with GenSSLCertsU help section.
Note: For Internal Testing purposes, it is highly recommended to use the Default IC Self Signed Certificate process done at the initial installation of PureConnect to validate that you have a fully functional IC System that you have verified that everything is up and running and switchover is fully functional before performing any other certificate work. That also means that the Media Server and any other Peripheral Off Host IC Sub-systems have been installed, Trusted, and functionality tested before you are satisfied that you have a fully functional IC system, then you can proceed with generating a new CSR for the Third Party Signed Certificate Mode use and then continue with any subsequent updating of the PureConnect Certificates.

