Configuring certificates for on-premise appliances


Note: Starting August 1, 2023, Zoom will require TLS certificates for the Meeting Connector, for a more secure communication method.

When configuring a Meeting Connector or Virtual Room Connector (VRC) appliance, admins can upload and use their own TLS certificates, issued by a trusted certificate authority (CA), for their appliances. However, these must be manually rotated prior to expiration. However, for Meeting Connector, admins can also configure the appliance to use certificates and domains managed and updated by Zoom automatically through Zoom's Auto PKI feature.

This article covers:

Prerequisites for configuring on-prem certificates and domains

How to manage a Zone Controller's certificates

Configuring a Zone controller to use a Zoom-managed certificate

Note: These TLS certificates are issued by trusted certificate authorities and utilize WebPKI for validation. 

  1. In your web browser, navigate to the appliance's web console: https://IPaddress:5480
  2. Sign in with admin credentials.
  3. In the navigation menu, click Configure.
  4. Enable Use domains and certificates managed by Zoom.
  5. Click Apply Domain & Certificate.
  6. Enter the IPv4 addresses for ZC External and MMR External.
    Note: The MMR External address needs to be entered in both the (8801 and 443 port fields).
  7. (Optional) enable Hide vanity from the domain.
  8. Click Apply domain & Certificate.
  9. Click OK.
    A success message will be displayed once the domain and certificate have been applied.
  10. Click OK.
  11. At the bottom of the page, click Submit to apply the changes and restart the meeting services.

Configuring a Zone Controller to use an organization’s managed certificates

Before installing the certificate, your organization must obtain a certificate from a WebPKI-compliant certificate authority. 

  1. In your web browser, navigate to the appliance's web console: https://IPaddress:5480
  2. Sign in with admin credentials.
  3. In the navigation menu, click Configure.
  4. Enable Use myself domains and upload certificates.
  5. Enter the domains for the ZC Internal Domain and MMR Internal Domain.
  6. Enter the IPv4 addresses for ZC External and MMR External.
    Note: The MMR External address needs to be entered in both the (8801 and 443 port fields).
  7. Click Upload Certificate.
  8. Select and upload the certificate and key files.
  9. At the bottom of the page, click Submit to apply the changes and restart the meeting services.

How to manage an MMR's certificates

Configuring an MMR to use a Zoom-manged certificate

Note: These TLS certificates are issued by trusted certificate authorities and utilize WebPKI for validation.

  1. In your web browser, navigate to the appliance's web console: https://IPaddress:5480
  2. Sign in with admin credentials.
  3. In the navigation menu, click Configure.
  4. Enable Use domains and certificates managed by Zoom.
  5. Click Apply Domain & Certificate.
  6. Enter the IPv4 addresses for MMR Internal Domain and MMR External IPv4 Address/Domain.
    Note: The MMR External IPv4 Address/Domain address needs to be entered in both the (8801 and 443 port fields).
  7. (Optional) enable Hide vanity from the domain.
  8. Click Apply domain & Certificate.
  9. Click OK.
    A success message will be displayed once the domain and certificate have been applied.
  10. Click OK.
  11. At the bottom of the page, click Submit to apply the changes and restart the meeting services.

Configuring an MMR to use an organization's managed certificates

Before installing the certificate, your organization must obtain a certificate from a WebPKI-compliant certificate authority. 

  1. In your web browser, navigate to the appliance's web console: https://IPaddress:5480
  2. Sign in with admin credentials.
  3. In the navigation menu, click Configure.
  4. Enable Use myself domains and upload certificates.
  5. Enter the MMR Internal Domain.
  6. In MMR External IPv4 Address/Domain enter the address or domains for the MMR.
  7. Enter the IPv4 addresses for MMR Internal Domain and MMR External IPv4 Address/Domain.
    Note: The MMR External IPv4 Address/Domain address needs to be entered in both the (8801 and 443 port fields).
  8. Click Upload Certificate.
  9. Select and upload the certificate and key files.
  10. At the bottom of the page, click Submit to apply the changes and restart the meeting services.

How to manage Virtual Room Connector certificates

  1. In your web browser, navigate to the appliance's web console: https://IPaddress:5480
  2. Sign in with admin credentials.
  3. In the navigation menu, click Configure.
  4. Enable Replace Certificate.
  5. Select and upload the certificate and key files.
  6. At the bottom of the page, click Submit to apply the changes and restart the meeting services.