Strategies for Certificate Handling
Figure 1. Solution Overview

SIPLP only accepts inbound SIP messages that are directed to the MX-ONE system. The official identification of the MX-ONE system are the LIMs host name, limX,. where X is the LIM number. So if a SIP phone shall logon to LIM2 in domain, mx.corp.net, it shall be addressed as lim2.mx.corp.net, matching name in the SAN field.
As the server certificate is to be used only for the MX-ONE LIMs, the MX-ONE system should be a sub-domain in the corporate network.
↑