How To | Create a Certificate for Third-Party Controls on UC Platforms

Learn how to generate a certificate for third-party controls on UC platforms, enabling you to seamlessly integrate and utilize these controls in your application without any compatibility issues.

Updated at May 23rd, 2024



The steps below should be carried out by an IT professional with an understanding of certificate handling and domain DNS settings.



To ensure secure communication between Q-SYS and UC third-party controls, it is recommended to use a public CA certificate and follow the instructions provided below. Zoom offers several other connection methods in addition to a public CA certificate. For more information on additional Zoom connection methods, please refer to the following article. 

Awareness | Zoom Rooms Third-Party Controls Alternate Connection Methods


Use the following steps for creating a certificate for Zoom and Google Third-Party controls:

  1. Use a browser to go to the IP address of your Q-SYS Core or click on the “Open Core Manager” link for your Core in Q-SYS Configurator. 
  2. Ensure that your Core is named how you would like it to be named in Network > Basic > Hostname 
  3. Navigate to Network > Date & Time and ensure that the date and time are correctly configured. 
  4. Navigate to Network > Services and ensure that HTTPS is enabled on the LAN that the Q-SYS Core and Zoom Room device will be connected to. 
  5. Navigate to Network > Certificates > Generate CSR 
  6. Fill out the form, ensuring that you have the correct information. 


    Unless otherwise specified by your IT team, you MUST include the fully qualified domain name under DNS names, e.g.,

  7. Once you have finished filling out the form, click the Generate CSR button. Download the file and have an IT Professional create the certificate.


    IT Professionals will need to ensure that they change internal DNS to match the DNS names that were entered in the DNS Names field of the CSR form. The certificate must be signed by a trusted certificate authority, rather than a self-signed certificate. More details can be found here

  8. Once the IT Professional has created the certificate, they should send an encrypted certificate back to you. Go to Network > Certificates > Device Certificate and click “Install Certificate”. Paste or upload the certificate and click “Install.” 
  9. Reboot the Q-SYS Core. (This step is necessary for the Core to complete the certificate installation.) 
  10. To ensure the certificate is valid, use Google Chrome to the the URL of your Q-SYS Core, including https:// ( You should see a secure connection indicator in Google Chrome, next to your URL. If your connection is not secure, work with an IT professional to ensure that the certificate and network environment is setup correctly.