<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate validation problem with CUCM SDB in DevNet General Discussions</title>
    <link>https://community.cisco.com/t5/devnet-general-discussions/certificate-validation-problem-with-cucm-sdb/m-p/3484114#M352</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ferenc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apologies for the delay in responding to you, I would request you to find this url - &lt;A href="https://community.cisco.com/message/189898"&gt;SSL Problem from CUCM&lt;/A&gt; for related information. And also post if there is any questions related to the topic under &lt;A href="https://community.cisco.com/space/4509"&gt;AXL&lt;/A&gt; community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Geevarghese&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Apr 2016 08:38:11 GMT</pubDate>
    <dc:creator>Geevarghese Cheria</dc:creator>
    <dc:date>2016-04-01T08:38:11Z</dc:date>
    <item>
      <title>Certificate validation problem with CUCM SDB</title>
      <link>https://community.cisco.com/t5/devnet-general-discussions/certificate-validation-problem-with-cucm-sdb/m-p/3484113#M351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’d like to configure a secure phone XML service in CUCM. I want to add a phone button service but using HTTPS protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;CUCM: not in mixed mode&lt;/LI&gt;&lt;LI&gt;Service certificate has been imported into CUCM as tomcat-trust&lt;/LI&gt;&lt;LI&gt;I have a service implemented as a Tomcat servlet and service has been bound into a phone service with these URLs:&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;Service URL:&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://192.168.5.36:8080/andphone/callback?page=missed&amp;amp;dev=#DEVICENAME#" target="_blank"&gt;http://192.168.5.36:8080/app/callback?page=missed&amp;amp;dev=#DEVICENAME#&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Secure-Service URL:&amp;nbsp;&amp;nbsp; &lt;A href="https://192.168.5.36:8443/andphone/callback?page=missed&amp;amp;dev=#DEVICENAME#" target="_blank"&gt;https://192.168.5.36:8443/&lt;/A&gt;&lt;A href="http://192.168.5.36:8080/andphone/callback?page=missed&amp;amp;dev=#DEVICENAME#" style="font-size: 13.3333330154419px;" target="_blank"&gt;app&lt;/A&gt;&lt;A href="https://192.168.5.36:8443/andphone/callback?page=missed&amp;amp;dev=#DEVICENAME#" target="_blank"&gt;/callback?page=missed&amp;amp;dev=#DEVICENAME#&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I push phone button and call the service I’ve get ‘Host not found’ message on phone device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a phone initializes a HTTPS connection to a server it validates server certificate from remote trust store (provided by CUCM). This is a SBD (Security by Default) Cisco feature.&lt;/P&gt;&lt;P&gt;In my environment phone is not able to validate server certificate because phone is not able to connect to&amp;nbsp; remote trust store (CUCM).&lt;BR /&gt; &lt;BR /&gt; It tries to access CUCM by DNS name, but it’s not supported (see in log above). &lt;/P&gt;&lt;P&gt;Is there any configuration issue in our environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log about CUCM SBD certificate validation downloaded from phone:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2867: NOT 16:25:59.512685 SECD: srvr_cert_vfy: Server Certificate Validation needs to be done&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2868: NOT 16:25:59.514375 SECD: findByIssuerAndSerialAndRoleInTL: Searching TL from CTL file &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2869: NOT 16:25:59.515189 SECD: findByIssuerAndSerialAndRoleInTL: Searching TL from ITL file &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2870: WRN 16:25:59.515895 SECD: WARN:getSubjectCTLentry: default lookup failed, try lookup using DN&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2871: NOT 16:25:59.516565 SECD: findByCertAndRoleInTL: Searching TL from CTL file &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2872: NOT 16:25:59.517240 SECD: findByCertAndRoleInTL: Searching TL from ITL file &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2873: ERR 16:25:59.517933 SECD: EROR:https_cert_vfy: HTTPS cert not in CTL, &amp;lt;192.168.5.36&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2874: NOT 16:25:59.522492 SECD: setupSocketToTvsProxy: TVS client sock fd 10 bound to &amp;lt;/tmp/secClntTvs_119_6359&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2875: NOT 16:25:59.523701 SECD: setupSocketToTvsProxy: Connected to TVS proxy server&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2876: NOT 16:25:59.524990 SECD: clpTvsInit: Client message received on TVS proxy socket&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2877: NOT 16:25:59.526147 SECD: processTvsClntReq: Success reading the client TVS request, len : 3708&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2878: NOT 16:25:59.526950 SECD: processTvsClntReq: TVS Certificate Authentication request&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2879: NOT 16:25:59.527660 SECD: lookupAuthCertTvsCacheEntry: No matching entry found at cache&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2880: NOT 16:25:59.528372 SECD: processTvsClntReq: No server sock exists, must be created&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2881: NOT 16:25:59.532634 SECD: getTvsServerInfo: Phone in IPv4 only mode&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2882: NOT 16:25:59.533333 SECD: getTvsServerInfo: Retreiving IPv4 address&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2883: NOT 16:25:59.533994 SECD: getTvsServerInfo: TVS retry count 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2884: NOT 16:25:59.534727 SECD: getTvsSrvrSock: TVS server info: IP : BAL-CUCM-01, tvsPort : 2445, ipMode : 0, timeout : 10, dscpValue : 96, srvrRetries : 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2885: NOT 16:25:59.535611 SECD: secSock_send_clnt_reqs: trying conn to &amp;lt;BAL-CUCM-01:2445&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2886: NOT 16:25:59.537932 SECD: secSock_send_clnt_reqs: SSL/TLS waiting, &amp;lt;BAL-CUCM-01:2445&amp;gt;, fd 13&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2887: NOT 16:25:59.538709 SECD: connectToTvsServer: Send buffer size on TVS server socket set to &amp;lt;4096&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2888: NOT 16:25:59.539443 SECD: connectToTvsServer: Successfully started a TLS connection establishment to the TVS server: IP:BAL-CUCM-01, port:2445(default); Waiting for it to get connected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2889: NOT 16:25:59.541687 SECD: tvsReqAuthenticateCertificate: Sent Request to TVS proxy, len: 3708&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2890: NOT 16:25:59.542430 SECD: tvsReqAuthenticateCertificate: Waiting for response from TVS Proxy&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2891: NOT 16:25:59.543341 SECD: clpGetConnParams: IP Mode is 0, addr : BAL-CUCM-01&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="color: #70ad47; background: yellow;"&gt;2892: ERR 16:25:59.544082 SECD: EROR:clpGetConnParams: Server address passed in as DNS name.Not supported in SECD&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2893: ERR 16:25:59.544787 SECD: EROR:clpSetupSsl: conn req has bad target addr &amp;lt;BAL-CUCM-01&amp;gt; c:14&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2894: ERR 16:25:59.545503 SECD: EROR:clpSetupSsl: SSL/TLS setup failed, &amp;lt;&amp;gt; c:14 s:-1&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2895: ERR 16:25:59.546222 SECD: EROR:clpSndStatus: SSL CLNT ERR, srvr&amp;lt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2896: ERR 16:25:59.546899 SECD: EROR:secErr_errStr:&amp;nbsp; *** bad err table ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2897: ERR 16:25:59.547587 SECD: EROR:secErr_errStr: ** SEC-ERR: code:1(N/A) subcode:10(BAD_ADDR)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2898: ERR 16:25:59.548244 SECD: EROR:clpSndStatus: ** SEC-ERR: desc &amp;lt;bad target addr&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2899: NOT 16:25:59.549137 SECD: clpTvsInit: select returned the TVS proxy server socket, fd : 13&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2900: ERR 16:25:59.549899 SECD: EROR:secSock_isConnected: ** failed to connect to target&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2901: ERR 16:25:59.550698 SECD: EROR:secErr_errStr:&amp;nbsp; *** bad err table ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2902: ERR 16:25:59.551398 SECD: EROR:secErr_errStr: ** SEC-ERR: code:1(N/A) subcode:10(BAD_ADDR)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2903: ERR 16:25:59.552068 SECD: EROR:secSock_isConnected: ** SEC-ERR: desc &amp;lt;bad target addr&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2904: ERR 16:25:59.552742 SECD: EROR:checkTvsSrvrConn: Failed to get TVS TLS session connected - setup failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 35.4pt;"&gt;&lt;SPAN lang="EN-US" style="color: #70ad47;"&gt;2905: NOT 16:25:59.553430 SECD: cleanupTvsSrvrSock: Clearing TVS proxy server socket, fd : 13&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2019 10:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/devnet-general-discussions/certificate-validation-problem-with-cucm-sdb/m-p/3484113#M351</guid>
      <dc:creator>tferitferi</dc:creator>
      <dc:date>2019-03-01T10:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate validation problem with CUCM SDB</title>
      <link>https://community.cisco.com/t5/devnet-general-discussions/certificate-validation-problem-with-cucm-sdb/m-p/3484114#M352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ferenc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apologies for the delay in responding to you, I would request you to find this url - &lt;A href="https://community.cisco.com/message/189898"&gt;SSL Problem from CUCM&lt;/A&gt; for related information. And also post if there is any questions related to the topic under &lt;A href="https://community.cisco.com/space/4509"&gt;AXL&lt;/A&gt; community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Geevarghese&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2016 08:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/devnet-general-discussions/certificate-validation-problem-with-cucm-sdb/m-p/3484114#M352</guid>
      <dc:creator>Geevarghese Cheria</dc:creator>
      <dc:date>2016-04-01T08:38:11Z</dc:date>
    </item>
  </channel>
</rss>

