Summary
- Avaya J1xx phones require different update methods depending on whether the Root Certificate Authority (RootCA) has changed—reboots work for identity cert updates, but a full factory clear is needed if the RootCA is replaced.
- You can update J1xx phones using the admin menu, automatic updates via 46xxsettings.txt, or by rebooting the phones to fetch new configurations from IP Office.
- Power cycling or remote reboots can trigger updates, but this won’t help if the phone can’t trust the server due to a mismatched RootCA.
- For phones running in 3PCC (third-party call control) mode, the update process remains the same—relying on the same config files and methods—especially when supported by a managed service like Atcom’s cloud phone system.
- Atcom recommends downloading and comparing the RootCA file before and after certificate updates, and we offer expert support to help businesses avoid downtime by managing J-series VoIP phones at scale.
If you’re managing Avaya J1xx-series VoIP phones—like the J129, J139, J159, J169, J179, or J189—you may eventually run into issues when updating your system’s SSL certificates.
One of the most common questions we get at Atcom Systems is whether these phones require a simple reboot or a full clear to update their SSL certificate configuration correctly.
If you get this wrong, your phones may fail to connect to your IP Office server entirely—leaving users without dial tone and your IT team scrambling.
We’ve been helping Canadian businesses deploy and maintain Avaya phone systems for years, and this guide will walk you through:
- When to reboot vs. clear your J1xx phone
- How to update phone firmware and settings
- What to do if you’re using 3PCC mode or Atcom’s managed cloud phone services
- How to avoid common pitfalls during SSL transitions
Let’s get down to business.
Reboot vs. Clear: What’s the Difference, & Why Does It Matter?
When you update SSL certificates on your IP Office, each connected J1xx phone needs to retrieve and trust the new certificate. But the way they do this depends on what changed:
Reboot (Soft Refresh)
Rebooting tells the phone to re-check for updates. This works only if the Root Certificate Authority (RootCA) hasn’t changed.
When to use it:
- If you’ve updated the identity certificate (not the RootCA)
- If the phone already trusts your RootCA
- If you just want the phones to fetch new settings or firmware
How it works:
- Phone checks its config server (usually your IP Office)
- Performs a “GET If-Modified” request
- Downloads the identity certificate only if newer than the one currently on the device
If the RootCA is still trusted, this method is fast and safe.
Clear (Factory Reset)
If you’ve changed the RootCA, the phones won’t be able to establish a secure connection to the server because the old certificate is no longer valid.
When to use it:
- If the RootCA in your IP Office system has changed
- If TLS connections to the config server are failing
- If rebooting does not resolve certificate errors
How to check it:
- Visit https://[your-IPOffice-address]/WebRootCA.pem in a browser
- Compare the certificate before and after changes
Be warned: If the RootCA has changed, you should typically clear each J1xx phone. Otherwise, they won’t trust your server and won’t update—which can cause connection issues.
3 Different Ways to Update Avaya J1xx Phones
Once you’ve confirmed whether a reboot or clear is necessary, you can push updates to your phones using one of the following methods:
1. Update from the Admin Menu (Manual “Get Updates”)
This option is great for individual phones or small deployments.
Steps:
- Press the “Hamburger” (three-line) button
- Navigate to Settings > Administration
- Enter the admin password (default: 27238)
- Scroll to “Get Updates” and select it
This forces the phone to check for updated firmware or config files from the IP Office.
2. Enable Automatic Updates in 46xxsettings.txt
This method is ideal for proactive IT teams managing many phones. It automatically enables phones to check for updates on a regular schedule.
Steps:
- Edit your 46xxsettings.txt or 46xxspecials.txt file
- Add AUTOMATIC_UPDATE_POLICY with your preferred parameters
- Distribute the updated config file to your phones
You must manually update phones (using method 1 or 3) at least once for them to recognize this new policy.
3. Reboot the Phones (Simple Restart)
This method triggers the phone to pull its configuration and check for updates. It ensures that settings and firmware are synced with your current IP Office server. It also resolves minor update issues that don’t require a full clear.
Ways to reboot:
- Power cycle the phone (turn it off and on again)
- Use remote management (if supported)
- Unplug/replug network or PoE connection (the same as power cycling if you have PoE)
Using J1xx Phones in 3PCC Mode? Here’s What You Need to Know
Many businesses use Avaya J1xx phones with third-party SIP services in a setup known as 3PCC, or “third-party call control.” This is common when connecting to cloud phone services like the ones Atcom provides.
Here’s some good news: the update process is essentially the same! You’ll still:
- Use 46xxsettings.txt files
- Update the same certificates
- Push updates via reboot or the admin menu
Best of all, if your J1xx phones are deployed through Atcom’s managed cloud phone service, our team can assist with provisioning and certificate updates to keep your system secure and current. This ensures your devices stay secure, reliable, and fully functional without the need for manual resets.
Best Practices for Managing SSL on J1xx Phones
- Before updating your certificate: Download the current RootCA from https://[IPOffice]/WebRootCA.pem
- After updating: Download the new RootCA and compare
- If they differ: Plan for a full factory reset of all J1xx phones
- Maintain your 46xx settings files and apply AUTOMATIC_UPDATE_POLICY proactively
- Use SET ENABLE_PUBLIC_CA_CERTS 1 to automatically trust common Certificate Authorities
- Trust two Certificate Authorities simultaneously using SET TRUSTCERTS
- Use Atcom’s provisioning tools for seamless remote updates
Keep Your Avaya J-Series SSL Certificate Up to Date with Help from Atcom Systems
SSL certificate issues can quietly break your phone system if you don’t catch them early. Our experienced team at Atcom Systems can help you:
- Determine whether reboot or clear is needed
- Manage 3PCC/AtcomCloud phones at scale
- Prevent downtime during certificate rotations
We’ve deployed and supported thousands of J-series phones across Canada. Let’s make sure yours are ready for whatever update comes next. Contact us today for solutions customized to your business needs.
Bill Atwood
Manager, Atcom Systems Inc. Located in Calgary, Alberta
Subscribe to our Newsletter for Updates and News

Headquartered in Calgary, supporting Canadian businesses
Atcom Systems is a Canadian leader in modern, efficient, and user-friendly solutions that meet the needs of clients in diverse industries and solve key communication challenges.














