Peering Hub¶
Document Metadata
Category: Setup / Application Store & App Deployment
Audience: Administrators, Engineers, Product Team
Difficulty: Intermediate
Time Required: Approximately 20–30 minutes
Prerequisites: Active ConnexCS account with Setup privileges; an iConnectiv (STI-PA) account for STIR/SHAKEN certificate provisioning; basic understanding of the Apps platform and STIR/SHAKEN concepts.
Related Topics: App Store
Next Steps: Generate a private key and certificate signing request in PeeringHub, submit it through iConnectiv (STI-PA), and once approved, deploy the certificate to your ConnexCS platform to begin signing outbound calls.
Overview¶
Peering Hub is a STIR/SHAKEN certificate management application that helps telecommunications service providers securely manage the complete lifecycle of STIR/SHAKEN certificates.
It simplifies the process of generating cryptographic keys, requesting certificates from an authorized Certification Authority (CA) through iConnectiv (STI-PA), and deploying certificates to ConnexCS platforms for signing outbound calls.
Why Use Peering Hub?¶
STIR/SHAKEN is an industry framework designed to combat caller ID spoofing by verifying the authenticity of telephone calls.
Peering Hub provides a centralized interface to:
- Generate and manage private/public key pairs.
- Request and renew STIR/SHAKEN certificates.
- Manage certificate deployments.
- Configure signing credentials for ConnexCS platforms.
- Monitor certificate status and validity.
Key Features¶
-
Private Key Management: Securely generate and store cryptographic private keys used for call signing.
-
Certificate Provisioning: Request and manage STIR/SHAKEN certificates through iConnectiv (STI-PA).
-
Certificate Deployment: Deploy approved certificates to ConnexCS platforms for outbound call authentication.
-
Certificate Lifecycle Management: Track certificate issuance, expiration, renewal, and replacement.
-
Centralized Administration: Manage all STIR/SHAKEN resources from a single application.
How It Works¶
flowchart TD
A[Generate Private Key] --> B[Create Certificate Request]
B --> C[Submit to iConnectiv STI-PA]
C --> D[Certificate Issued]
D --> E[Deploy Certificate]
E --> F[Sign Outbound Calls]
F --> G[Verify Caller Identity]
Typical Workflow¶
- Generate a cryptographic key pair.
- Create a certificate signing request (CSR).
- Submit the request through iConnectiv (STI-PA).
- Receive the approved STIR/SHAKEN certificate.
- Deploy the certificate to the ConnexCS platform.
- Outbound calls are digitally signed, allowing receiving carriers to verify the caller's identity.
Benefits¶
- Reduces caller ID spoofing.
- Improves trust in outbound calls.
- Simplifies STIR/SHAKEN certificate management.
- Centralizes certificate deployment and renewal.
- Helps service providers comply with STIR/SHAKEN requirements.
How to use Peering Hub?¶
-
Navigate to Setup App Store Peering Hub and click
Install.
-
A window will appear, hit
Installagain.
-
In the
Installed Versionstab clickConfig. This section is used to configure the API endpoint that the Peering Hub application uses to communicate with the Peering Hub service. The configured URL is used for all requests related to STIR/SHAKEN certificate management.
-
A window will open, prompting you to enter the following details:
API Base URL: Specify the base URL of the Peering Hub API. The application sends all requests, such as certificate provisioning, key management, and deployment, to this endpoint. Only change this value if you need to connect to a different Peering Hub environment, such as a testing or private deployment.- Click
Saveto apply and store the configured API Base URL. All future requests from the Peering Hub application will use the saved endpoint. - Click
Reset to Defaultto restore the API Base URL to the default Peering Hub endpoint (https://app-api.peeringhub.io). Use this option to discard any custom configuration and reconnect to the default service.
-
Navigate to Setup Information STIR/SHAKEN Cert. Click on the
PeeringHubbutton.
-
Sign in to PeeringHub.
After login you can directly migrate your certificate.