<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Jabber in iPhone 11 pro getting Certificate error in IP Telephony and Phones</title>
    <link>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4053428#M387563</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325806"&gt;@Jaime Valencia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank&lt;SPAN&gt;&amp;nbsp;you so much for all your time and response, I really do appreciate it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Yes&lt;/STRONG&gt;, i do see the certificates in the device´s trust store after accepting&amp;nbsp;them.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, have you confirmed that those are indeed your certificates and that they do match the CN and the actual server's FQDN/hosntame?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;Yes&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My friend has suggested me to follow below steps, I will try this &amp;amp; ll let you know whether its work for me /not&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;" Reset the Jabber on the iPhone Pro 11&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which should go ahead and erase all the existing certificates from the device.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;As soon as you have the fresh prompt on the application, Login to your Jabber Client, and Click OK on the prompt.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;This might just add the certs automatically to your Jabber Client’s Trust List. If not, then go to step 3.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then go to:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Settings &amp;gt; General &amp;gt; About &amp;gt; Certificate Trust Settings.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Under&amp;nbsp;&lt;STRONG&gt;"Enable full trust for root certificates,"&lt;/STRONG&gt;&amp;nbsp;turn ON trust for the certificate.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Confirm the same on the device, if it shows as on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;A title="Original URL: https://support.apple.com/en-in/HT204477. Click or tap if you trust this link." href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fen-in%2FHT204477&amp;amp;data=02%7C01%7Cdawood.sheakh%40wipro.com%7Cde85cea0bc4e494a21b108d7d16ad347%7C258ac4e4146a411e9dc879a9e12fd6da%7C0%7C0%7C637208129083773521&amp;amp;sdata=0EIrlIH2nD8J49cR58z%2BrUOYgA2NBakt8Z0xCqXTtD4%3D&amp;amp;reserved=0" target="_blank" rel="noopener noreferrer"&gt;https://support.apple.com/en-in/HT204477 "&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Mar 2020 07:22:25 GMT</pubDate>
    <dc:creator>Rocky8971</dc:creator>
    <dc:date>2020-03-27T07:22:25Z</dc:date>
    <item>
      <title>Jabber in iPhone 11 pro getting Certificate error</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4052618#M387524</link>
      <description>&lt;P&gt;When our clients are logged in to Jabber there are 2 pop-ups for certificate warning when he accepts all the certificate pop-ups again error gets pop-up&lt;STRONG&gt;(Repeatedly for every 2 min).&lt;/STRONG&gt;&lt;BR /&gt;How is it possible to disable this warning? Can anyone help me? Is it still a bug or am I doing something wrong?&lt;BR /&gt;The only certificate alerts I see are for &lt;STRONG&gt;when the Client connects internally.&lt;/STRONG&gt;&lt;BR /&gt;CUCM Version:- &lt;STRONG&gt;11.5.1&lt;/STRONG&gt;&lt;BR /&gt;Using a &lt;STRONG&gt;Self-signed certificate.&lt;/STRONG&gt;&lt;BR /&gt;The Screenshot attached shows errors from what looks like the TFTP Server.&lt;BR /&gt;The Client is also connected to WiFi, looks like they may be able to reach the&lt;STRONG&gt; internal network.&lt;/STRONG&gt;&lt;BR /&gt;Configurations in Android and CUCM are the same in both situations. Nothing is changed.&lt;BR /&gt;Please find in attachment the error message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Jabber error snap.JPEG" style="width: 461px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69965i847239F1DB6923D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Jabber error snap.JPEG" alt="Jabber error snap.JPEG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2020-03-24 16:44:24,277 INFO [0x000000010718d840] [i/ui/cert/YLCInvalidCertAlertView.m(118)] [UI.Action.User] [-[YLCInvalidCertAlertView initWithDerCertificate:referenceID:certName:response:allowUserAccept:persistAcceptedDecision:]_block_invoke] - user accpet the Certificate Alert for NILcucmsub2.nilesuq.com,and persistAcceptedDecision value is 1&lt;/P&gt;&lt;P&gt;2020-03-24 16:44:24,277 DEBUG [0x000000010718d840] [/InvalidCertNotificationManager.cpp(372)] [csf.cert] [acceptInvalidCert] - User has accepted the request with fingerprint b5 d4 bf 78 bf 7e 10 53 b9 3a 5e 54 61 39 6f 24&lt;/P&gt;&lt;P&gt;2020-03-24 16:44:24,277 DEBUG [0x000000010718d840] [/InvalidCertNotificationManager.cpp(396)] [csf.cert] [acceptInvalidCert] - Signal has been sent.&lt;/P&gt;&lt;P&gt;2020-03-24 16:45:25,989 INFO [0x000000010718d840] [i/ui/cert/YLCInvalidCertAlertView.m(118)] [UI.Action.User] [-[YLCInvalidCertAlertView initWithDerCertificate:referenceID:certName:response:allowUserAccept:persistAcceptedDecision:]_block_invoke] - user accpet the Certificate Alert for nilesuq.in,and persistAcceptedDecision value is 1&lt;/P&gt;&lt;P&gt;2020-03-24 16:45:25,989 DEBUG [0x000000010718d840] [/InvalidCertNotificationManager.cpp(372)] [csf.cert] [acceptInvalidCert] - User has accepted the request with fingerprint cb fd bb 66 cb 7c f1 69 82 49 bf af 19 bd 2e f7&lt;/P&gt;&lt;P&gt;2020-03-24 16:45:25,989 DEBUG [0x000000010718d840] [/InvalidCertNotificationManager.cpp(396)] [csf.cert] [acceptInvalidCert] - Signal has been sent.&lt;/P&gt;&lt;P&gt;2020-03-24 17:12:21,073 INFO [0x0000000106f7d840] [i/ui/cert/YLCInvalidCertAlertView.m(118)] [UI.Action.User] [-[YLCInvalidCertAlertView initWithDerCertificate:referenceID:certName:response:allowUserAccept:persistAcceptedDecision:]_block_invoke] - user accpet the Certificate Alert for NILCUCMSUB2.nilesuq.com,and persistAcceptedDecision value is 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line 23099: 2020-03-25 14:22:23,636 INFO [0x0000000107001840] [i/ui/cert/YLCInvalidCertAlertView.m(118)] [UI.Action.User] [-[YLCInvalidCertAlertView initWithDerCertificate:referenceID:certName:response:allowUserAccept:persistAcceptedDecision:]_block_invoke] - user accpet the Certificate Alert for NILIMPSUB2.nilesuq.com,and persistAcceptedDecision value is 1&lt;/P&gt;&lt;P&gt;Line 35503: 2020-03-25 14:23:29,569 INFO [0x000000010b905840] [i/ui/cert/YLCInvalidCertAlertView.m(118)] [UI.Action.User] [-[YLCInvalidCertAlertView initWithDerCertificate:referenceID:certName:response:allowUserAccept:persistAcceptedDecision:]_block_invoke] - user accpet the Certificate Alert for NILCUCMSUB3.nilesuq.com,and persistAcceptedDecision value is 1&lt;/P&gt;&lt;P&gt;Line 35504: 2020-03-25 14:23:29,569 DEBUG [0x000000010b905840] [/InvalidCertNotificationManager.cpp(372)] [csf.cert] [acceptInvalidCert] - User has accepted the request with fingerprint b5 d4 bf 78 bf 7e 10 53 b9 3a 5e 54 61 39 6f 24&lt;/P&gt;&lt;P&gt;Line 35505: 2020-03-25 14:23:29,569 DEBUG [0x000000010b905840] [/InvalidCertNotificationManager.cpp(396)] [csf.cert] [acceptInvalidCert] - Signal has been sent.&lt;/P&gt;&lt;P&gt;Line 43890: 2020-03-25 14:23:31,406 DEBUG [0x000000010b905840] [/InvalidCertNotificationManager.cpp(372)] [csf.cert] [acceptInvalidCert] - User has accepted the request with fingerprint cb fd bb 66 cb 7c f1 69 82 49 bf af 19 bd 2e f7&lt;/P&gt;&lt;P&gt;Line 43891: 2020-03-25 14:23:31,406 DEBUG [0x000000010b905840] [/InvalidCertNotificationManager.cpp(396)] [csf.cert] [acceptInvalidCert] - Signal has been sent.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;looking into the logs i noticed :-&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;020-03-25 11:37:52,791 INFO [0x000000010706d840] [i/ui/cert/YLCInvalidCertAlertView.m(175)] [UI.Cert] [-[YLCInvalidCertAlertView isCertificateAlreadySaved]] - Certificate for NILIMPSUB2.NIL.comnot exists&lt;BR /&gt;2020-03-25 11:37:52,791 INFO [0x000000010706d840] [ui/util/YLCAlertControllerManager.m(392)] [UI.Action.System] [-[YLCAlertControllerManager showAlertController:onView:withRect:]] - jabber show alert to user (Cisco Jabber cannot confirm the identity of the server NILIMPSUB2.NIL.com. Do you want to continue?&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;Also, could notice the following:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;I&gt;&lt;SPAN&gt;2020-03-24 16:44:20,905 ERROR [0x000000016fecb000] [ls/src/cert/ios/iOSCertVerifier.cpp(186)] [csf.cert.ios] [verifyCertificatePolicy] - Policy verification failed, the urls of CRL Distribution Points and Authority Information Access might be unreachable, result=5&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 11:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4052618#M387524</guid>
      <dc:creator>Rocky8971</dc:creator>
      <dc:date>2020-03-26T11:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Jabber in iPhone 11 pro getting Certificate error</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4052954#M387538</link>
      <description>&lt;P&gt;Do you see the certificates in the device´s trust store (I think apple calls it a different way, but you get the idea) after you accept them?&lt;/P&gt;
&lt;P&gt;If not, try to install them before using Jabber either manually or via MDM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, have you confirmed that those are indeed your certificates and that they do match the CN and the actual server's FQDN/hosntame?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 15:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4052954#M387538</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2020-03-26T15:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Jabber in iPhone 11 pro getting Certificate error</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4053428#M387563</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325806"&gt;@Jaime Valencia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank&lt;SPAN&gt;&amp;nbsp;you so much for all your time and response, I really do appreciate it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Yes&lt;/STRONG&gt;, i do see the certificates in the device´s trust store after accepting&amp;nbsp;them.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, have you confirmed that those are indeed your certificates and that they do match the CN and the actual server's FQDN/hosntame?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;Yes&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My friend has suggested me to follow below steps, I will try this &amp;amp; ll let you know whether its work for me /not&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN&gt;" Reset the Jabber on the iPhone Pro 11&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, which should go ahead and erase all the existing certificates from the device.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;As soon as you have the fresh prompt on the application, Login to your Jabber Client, and Click OK on the prompt.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;This might just add the certs automatically to your Jabber Client’s Trust List. If not, then go to step 3.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then go to:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Settings &amp;gt; General &amp;gt; About &amp;gt; Certificate Trust Settings.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Under&amp;nbsp;&lt;STRONG&gt;"Enable full trust for root certificates,"&lt;/STRONG&gt;&amp;nbsp;turn ON trust for the certificate.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Confirm the same on the device, if it shows as on the link:&amp;nbsp;&lt;/SPAN&gt;&lt;A title="Original URL: https://support.apple.com/en-in/HT204477. Click or tap if you trust this link." href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fen-in%2FHT204477&amp;amp;data=02%7C01%7Cdawood.sheakh%40wipro.com%7Cde85cea0bc4e494a21b108d7d16ad347%7C258ac4e4146a411e9dc879a9e12fd6da%7C0%7C0%7C637208129083773521&amp;amp;sdata=0EIrlIH2nD8J49cR58z%2BrUOYgA2NBakt8Z0xCqXTtD4%3D&amp;amp;reserved=0" target="_blank" rel="noopener noreferrer"&gt;https://support.apple.com/en-in/HT204477 "&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 07:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/jabber-in-iphone-11-pro-getting-certificate-error/m-p/4053428#M387563</guid>
      <dc:creator>Rocky8971</dc:creator>
      <dc:date>2020-03-27T07:22:25Z</dc:date>
    </item>
  </channel>
</rss>

