Upload SHAKEN Certificate and Private Key

This topic describes how to upload a SHAKEN certificate and its corresponding private key to NovoOne platform. The private key is used by the system to sign outbound calls, while the certificate enables called parties to verify the authenticity of those calls.

Prerequisites

Before you begin, ensure you have prepared the following:

  • You have generated an ECDSA key pair using the P-256 curve, and stored the private key securely.

  • You have submitted a certificate signing request containing the public key to the STI-CA (Secure Telephone Identity Certification Authority), and obtained a valid SHAKEN certificate that meets the following requirements:
    • Signature algorithm: ECDSA with SHA-256 (ES256)
    • Format: .cer, .crt, or .pem

Procedure

  1. Log in to NovoOne Platform portal, go to SIP Trunks > STIR/SHAKEN.
  2. In the Signature Certificate Management section, complete the following settings.

    1. In the Public Certification field, click to upload the SHAKEN certificate.
    2. In the Private Key field, click to upload the private key.
      Note: The private key must match the public key in the uploaded SHAKEN certificate.
  3. Click Save.

Result

The certificate is uploaded successfully and is automatically applied to all your trunks in the system.

What to do next

Enable Outbound Call Signing for a Trunk.