71301T · Question #9
You are setting up the SIP connection between Avaya Aura® Messaging (AAM) and the Avaya Aura® Core, and the information you have entered for the Far-end connection is: What should you conclude from…
The correct answer is C. A Security Certificate from the same Certificate Authority as the other Avaya Aura® components. When TLS is configured on port 5061 for a SIP connection, the conclusion is that a Security Certificate from the same Certificate Authority (CA) as the other Avaya Aura® components is required - because TLS mutual authentication depends on all endpoints trusting the same CA…
Question
You are setting up the SIP connection between Avaya Aura® Messaging (AAM) and the Avaya Aura® Core, and the information you have entered for the Far-end connection is: What should you conclude from all this information?
Options
- AThe connection cannot work because 5061 is not the Well-known port corresponding to TLS by
- BThere will be conflicts in the TLS connections given that 5061 is a well-known port that other
- CA Security Certificate from the same Certificate Authority as the other Avaya Aura® components,
- DThe IP address is wrong because its range does not correspond to a valid TLS-compatible IP
How the community answered
(44 responses)- A7% (3)
- B14% (6)
- C75% (33)
- D5% (2)
Explanation
When TLS is configured on port 5061 for a SIP connection, the conclusion is that a Security Certificate from the same Certificate Authority (CA) as the other Avaya Aura® components is required - because TLS mutual authentication depends on all endpoints trusting the same CA, which is the standard PKI model within an Avaya Aura® deployment.
Why the distractors are wrong:
- A is incorrect because 5061 is the IANA-assigned well-known port for SIP over TLS - it's the correct port, not an invalid one.
- B is incorrect because using a well-known port is standard and expected; it does not inherently cause conflicts.
- D is incorrect because there is no such concept as a "TLS-compatible IP address range" - TLS is a transport-layer protocol independent of IP address ranges.
Memory tip: Think "TLS = Trust" - whenever you see port 5061 (SIP/TLS), your immediate next thought should be certificates and CA trust chains. In any Avaya Aura® environment, components authenticate each other via TLS certificates, so a shared CA is always a prerequisite for TLS-secured SIP to function.
Topics
Community Discussion
No community discussion yet for this question.