Skip to main content

Certificate Authorities

Navigation: Admin → Telephony → Certificate Authorities Last verified: Genesys Cloud Resource Center — March 2026


What Are Certificate Authorities?

Certificate Authorities (CAs) in Genesys Cloud are used to manage trusted digital certificates for secure TLS connections in telephony. Genesys supports two certificate types: Managed and Remote.

⚠️ This page applies primarily to BYOC Premises deployments. For BYOC Cloud TLS trunk configuration, refer to the BYOC Cloud TLS trunk transport documentation instead.


Certificate Types

TypeWho Manages ItPurposeEditable?
ManagedGenesysCreates trusted TLS connections for the Edge and managed phones; allows remote SIP devices to trust secure connections to external trunks connected to the EdgeNo — cannot be added, edited, or deleted
RemoteCustomer (you)Imported CA that allows the Edge to trust a remote TLS endpoint such as an SBC or PBXYes — can be added, edited, and deleted

ℹ️ There is only one managed certificate per organization. Genesys maintains it automatically.


Navigation

TaskPath
Open Certificate AuthoritiesAdmin → Telephony → Certificate Authorities
Add remote certificate authorityCertificate Authorities → Add
Edit remote certificate authorityCertificate Authorities → select entry → Edit
Delete remote certificate authorityCertificate Authorities → select entry → Delete

Required permission: Telephony > Plugin > All


Adding a Remote Certificate Authority

StepAction
Step 1Navigate to Admin → Telephony → Certificate Authorities
Step 2Click Add
Step 3Choose import method: Upload from computer or Paste text from a file
Step 4Upload the .crt file or paste the certificate text
Step 5In Select Service for Use, choose the appropriate telephony service(s)
Step 6Click Save Certificate Authority
Step 7Test the secure TLS connection to the remote endpoint

UI Fields

FieldDescription
Type columnIdentifies whether the CA is Managed or Remote
Common NameCertificate authority common name
Add Certificate AuthorityImport method selector — Upload from computer or Paste text from a file
BrowseOpens file browser to locate the .crt file
Enter Your Certificate AuthorityText box for pasted certificate contents
Select Service for UseAssociates the CA with one or more telephony services
Save Certificate AuthoritySaves the new or edited remote CA

Key Rules

RuleDetail
Managed CAs are read-onlyCannot be added, edited, or deleted
Remote CAs are fully manageableAdd, edit service associations, or delete as needed
Supported import formats.crt file upload or pasted certificate text
BYOC Premises scopeThis feature area is for BYOC Premises; BYOC Cloud has its own TLS trunk documentation

When to Use a Remote Certificate Authority

SituationAction
BYOC Premises Edge must trust a remote SBC or PBX TLS endpointImport remote CA
Remote carrier presents a certificate signed by an internal/private CAImport remote CA
Managed phones require trusted TLSUse the Genesys-managed CA — no action needed
BYOC Cloud TLS trunk setupDo NOT use this page — use BYOC Cloud TLS trunk transport documentation

Troubleshooting

IssueCauseResolution
Remote TLS endpoint not trustedRequired remote CA not importedImport the correct CA and assign service usage
Cannot edit certificate authoritySelected CA is of type ManagedManaged CAs are read-only — only Remote CAs can be edited
Service still fails after importWrong certificate or wrong service associationRecheck the certificate chain and selected service(s)
Admin cannot access CA managementMissing permissionGrant Telephony > Plugin > All
Used wrong workflow for BYOC CloudThis page is for BYOC PremisesUse the BYOC Cloud TLS trunk transport documentation instead

Quick Reference

QuestionAnswer
What two certificate types exist?Managed and Remote
Who manages the Managed CA?Genesys
What is a Remote CA used for?Allows the Edge to trust a remote TLS endpoint
How can a remote CA be imported?Upload from computer or paste text from a file
Can Managed CAs be edited?No
Does this apply to BYOC Cloud?No — BYOC Cloud has its own TLS trunk documentation

See Also

  • Trunks — configure SIP connectivity; TLS transport is selected per trunk
  • Edges & Edge Groups — BYOC Premises media appliances that rely on CA trust
  • Sites — telephony routing configuration

Screenshots

Create New