MIKEY Option 0 is used if the signaling connection is secured via
TLS (Hop-by-Hop). This is ensured for all end-to-end payload streams
for the (DMC) master connection of an OpenScape 4000 node in which all
sections support signaling encryption.
Thus, no certificates are needed for MIKEY Option 0 itself but the
OpenScape 4000 systems or their gateways need an own (server) certificate
plus private key for TLS purposes.
All involved entities need the certificate of that/these CAs that
issue the certificates for the OpenScape 4000 systems / gateways.
If CRL (Certificate Revocation List) checks
are required by the configuration, the CRL DP (CRL Distribution
Point - HTTP/LDAP-URL) is required by every endpoint and must
therefore also be distributed.