<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did you reboot your JG server in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905135#M11090</link>
    <description>&lt;P&gt;Did you reboot your JG server to make the configuration take effect?&lt;/P&gt;
&lt;P&gt;If you actually rebooted your server, what's the java version on that server? try command "java -version" in terminal, and let us know (may still use an old JDK version)&lt;/P&gt;</description>
    <pubDate>Sun, 05 Feb 2017 15:26:09 GMT</pubDate>
    <dc:creator>niliu2</dc:creator>
    <dc:date>2017-02-05T15:26:09Z</dc:date>
    <item>
      <title>Jabber Guest doesn't work with Expressway 8.7.2</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905124#M11079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the latest Expressway requires Diffie-Hellman keys to be at least 1024 bits in size.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately Jabber Guest still uses 768bits as the "Server Temp Key" on tomcat. Therefore you can't use Jabber Guest (doesn't matter which version; I tried 10.6.9 and 10.6.10) with Expressway 8.7.2.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I also checked the settings of Tomcat and there is the appropriate setting in /opt/cisco/jabber/conf/mss-sip-stack-properties (which I assume that it is the relevant file):&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# support 2048 bits for Ephemeral Diffie-Hellman Keys&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;jdk.tls.ephemeralDHKeySize=2048&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately this doesn't work or at least the results are not as expected.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Trying to connect with openssl (openssl s_client -connect &amp;lt;JabberGuestServer&amp;gt;:5061) shows:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-- snip --&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Client Certificate Types: RSA sign, DSA sign&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1:RSA+MD5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Shared Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Peer signing digest: SHA512&lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;Server Temp Key: DH, 768 bits&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;---&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SSL handshake has read 3205 bytes and written 210 bytes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;---&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA256&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Server public key is 4096 bit&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Secure Renegotiation IS supported&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Compression: NONE&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Expansion: NONE&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;No ALPN negotiated&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-- snip --&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Expressway show "&lt;STRONG&gt;dh key too small&lt;/STRONG&gt;" in the log-file and "&lt;STRONG&gt;TLS negotiation failure&lt;/STRONG&gt;" the when checking the zone status.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It works perfectly with Expressway 8.6.1 (haven't tried 8.7.1 so far).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Log-Files / dumps / Screen-shots are available upon request, but I think the problem is quite clear and hopefully it will be easy to solve.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks and best regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 01:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905124#M11079</guid>
      <dc:creator>WolSen000</dc:creator>
      <dc:date>2019-03-18T01:01:20Z</dc:date>
    </item>
    <item>
      <title>That's related to this bug</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905125#M11080</link>
      <description>&lt;P&gt;That's related to this bug&lt;/P&gt;
&lt;DIV class="bugTitle"&gt;Jabber Guest fails after upgrade from 8.7.1 to 8.7.2&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;CSCuz13551&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;You can get in touch with your SE/AM for more details, as it's not publicly visible.&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Apr 2016 00:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905125#M11080</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2016-04-12T00:36:23Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905126#M11081</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Could you send me the java version in Jabber Guest server? &amp;nbsp;run this command "&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;java -version&lt;/STRONG&gt;" on Jabber Guest server terminal.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;In our lab environment, Jabber Guest(10.6.9 and 10.6.10) works fine with Expressay 8.7.2,Jabber Guest 10.6.9 and above has set the DH key to 1028 bits,connect to our lab Jabber Guest through openssl ,show below info:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;--snip----&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Client Certificate Types: RSA sign, DSA sign, ECDSA sign&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1:RSA+MD5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Shared Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Peer signing digest: SHA512&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;SPAN class="s1"&gt;Server Temp Key: DH, 1024 bits&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;---&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;SSL handshake has read 2626 bytes and written 242 bytes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;---&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;----snip-----&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 05:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905126#M11081</guid>
      <dc:creator>yjin2</dc:creator>
      <dc:date>2016-04-12T05:03:04Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905127#M11082</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the fast reply.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The java version is:&lt;/P&gt;
&lt;P&gt;java version "1.7.0_51"&lt;BR /&gt;OpenJDK Runtime Environment (rhel-2.4.4.1.el6_5-x86_64 u51-b02)&lt;BR /&gt;OpenJDK 64-Bit Server VM (build 24.45-b08, mixed mode)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The server has been upgraded several times since the initial install, but without any problems so far.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 06:37:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905127#M11082</guid>
      <dc:creator>WolSen000</dc:creator>
      <dc:date>2016-04-12T06:37:55Z</dc:date>
    </item>
    <item>
      <title>It's really weird, the first</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905128#M11083</link>
      <description>&lt;P&gt;It's really weird, the first official release version of Jabber guest is 10.0 ,I check the java version on Jabber guest 10.0 ,the version is "1.7.0_55".&lt;/P&gt;
&lt;P&gt;Where do you get the image for initial install? Have you ever install any external rpm on Jabber guest server ?&lt;/P&gt;
&lt;P&gt;PLease Jabber Guest log to us :Cisco Jabber Guest Administration-&amp;gt;Logs-&amp;gt;Download All&lt;/P&gt;
&lt;P&gt;Btw,please run command "rpm -qa" on Jabber Guest server terminal and send us the list.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 07:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905128#M11083</guid>
      <dc:creator>yjin2</dc:creator>
      <dc:date>2016-04-12T07:58:55Z</dc:date>
    </item>
    <item>
      <title>Ok, in this case maybe an</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905129#M11084</link>
      <description>&lt;P&gt;Ok, in this case maybe an explanation could be that it has been upgraded from the EAP Trial setup.&lt;/P&gt;
&lt;P&gt;So the installation base image is/was one of the EAP ova's. Most probably the JabberGuest-10.6.5.65.ova, but I'm not sure at the moment. I'll deploy a new machine later on to investigate.&lt;/P&gt;
&lt;P&gt;If that's the cause it might be easier to just reinstall my two JabberGuest servers from a clean-image, I think.&lt;/P&gt;
&lt;P&gt;I've attached the output of the "rpm -qa" here, the logs will follow later on.&lt;/P&gt;
&lt;P&gt;I haven't installed or changed anything else on the servers beside the original updates.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry to bother you if it's really related to the EAP-Trial installation&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 10:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905129#M11084</guid>
      <dc:creator>WolSen000</dc:creator>
      <dc:date>2016-04-12T10:30:23Z</dc:date>
    </item>
    <item>
      <title>Ok, I did some investigation</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905130#M11085</link>
      <description>&lt;P&gt;Ok, I did some investigation and I found out that the basic image which was used for the JabberGuest installation must have been a very, very old one (VMware states 1.0.6.101).&lt;/P&gt;
&lt;P&gt;I did a fresh install from the JabberGuest-10.6.5.65.ova and checked the Java version there. It was the 1.7.0_75 and the upgrade to JabberGuest-10.6.10.11 performed a rpm-upgrade (never saw that before) which brought Java to 1.8.0_72.&lt;/P&gt;
&lt;P&gt;After that the openssl connectivity test shows:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Client Certificate Types: RSA sign, DSA sign, ECDSA sign&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1:RSA+MD5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Shared Requested Signature Algorithms: ECDSA+SHA512:RSA+SHA512:ECDSA+SHA384:RSA+SHA384:ECDSA+SHA256:RSA+SHA256:ECDSA+SHA224:RSA+SHA224:ECDSA+SHA1:RSA+SHA1:DSA+SHA1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Peer signing digest: SHA512&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Server Temp Key: ECDH, P-256, 256 bits&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I also did a quick test with an Expressway 8.7.2 and now everything works perfectly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I deeply apologize for this mistake. I should have checked into this before posting here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help and best regards&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 14:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905130#M11085</guid>
      <dc:creator>WolSen000</dc:creator>
      <dc:date>2016-04-12T14:47:42Z</dc:date>
    </item>
    <item>
      <title>Hey Everyone,</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905131#M11086</link>
      <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just hit this issue with a customer and want to provide an update providing clarification.&amp;nbsp; June 2015 OpenSSL 2015 Logjam vulnerability was identified by OpenSSL causing multiple defects filed against Cisco Products that use OpenSSL.&amp;nbsp; Specifics Below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150612-openssl"&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150612-openssl&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.openssl.org/news/secadv/20150611.txt"&gt;https://www.openssl.org/news/secadv/20150611.txt&lt;/A&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;OpenSSL Security Advisory [11 Jun 2015]
=======================================

DHE man-in-the-middle protection (Logjam)
====================================================================

A vulnerability in the TLS protocol allows a man-in-the-middle
attacker to downgrade vulnerable TLS connections using ephemeral
Diffie-Hellman key exchange to 512-bit export-grade cryptography. This
vulnerability is known as Logjam (CVE-2015-4000).

OpenSSL has added protection for TLS clients by rejecting handshakes
with DH parameters shorter than 768 bits. This limit will be increased
to 1024 bits in a future release.

OpenSSL 1.0.2 users should upgrade to 1.0.2b
OpenSSL 1.0.1 users should upgrade to 1.0.1n

Fixes for this issue were developed by Emilia Käsper and Kurt Roeckx
of the OpenSSL development team.&lt;/PRE&gt;
&lt;P&gt;The specific defect against Jabber Guest is here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuu83421"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuu83421&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Starting in JabberGuest 10.6.9 and higher us a 1024 DH Key instead of the 768 DH key size used before 10.6.9.&amp;nbsp; Couple this with the new VCS X8.7.2 also addressing this vulnerability with its CiscoSSL update no longer accepting DH keys smaller than 1024.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/release_note/Cisco-VCS-Release-Note-X8-7-2.pdf#page-"&gt;www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/release_note/Cisco-VCS-Release-Note-X8-7-2.pdf#page=3 &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This issue specifically can occur when during a Call the remote client Bridge or Endpoint requests a FPU(Fast Picture Update) in the form of a SIP INFO message from the JabberGuest client.&amp;nbsp; If the VCS/Exp decides to create a new TCP connection back to JabberGuest on 5061 it will cause a new TLS Handshake to form where JabberGuest is the Server offering DH of 768 causing the DH key size reject.&amp;nbsp; As this new TCP connection isn't always created, meaning the original socket opened from JabberGuest to Expressway, the issue can be see intermittently.&lt;/P&gt;
&lt;P&gt;This should clarify the issues being seen between Expressway(VCS) and Jabber Guest where "dh key size too small" error is seen in the Logs, or the behavior of call setup then torn down after a short period of time.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Example of Exp/VCS Logs show DH Key Failure:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2016-04-09T20:05:42+00:00 lslilt01vce tvcs: Event="Outbound TLS Negotiation Error" Service="SIP" Src-ip="192.x.x.x" Src-port="10000" Dst-ip="10.x.x.x" Dst-port="5061" Detail="&lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;dh key too small&lt;/SPAN&gt;&lt;/STRONG&gt;" Protocol="TLS" Level="1" UTCTime="2016-04-09 20:05:42,220"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;PCAP from Exp/VCS showing fatal alert on TLS Handshake back to Jabber Guest:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;"Alert (Level: Fatal, Description: Handshake Failure)"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The follow command can be used to verify via root from JabberGuest itself or another device such as a VCS that has openssl: &amp;lt;JGIP&amp;gt; being your Jabber Guest server IP (Note 127.0.0.1 from root on JG will not work, must use configured IP of JabberGuest)&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;openssl s_client -connect &amp;lt;JGIP&amp;gt;:5061 -cipher "EDH" | grep "Server Temp Key"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&lt;SPAN style="font-size: 14pt;"&gt;&lt;STRONG&gt;Further Testing in the Lab:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&lt;SPAN style="font-size: 14pt;"&gt;Jabber Guest 10.6.8 doesn't seem to resolve the issue of the 768 DH Key per lab testing.&amp;nbsp; 10.6.9 however does seem to correct the DH Key to 1024.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&lt;SPAN style="font-size: 14pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;NOTE: After performing the upgrade you must reboot the JabberGuest server for the "new" DH key size configuration to take affect.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;____________________&lt;BR /&gt;LAB RECREATE w/ 10.6.8:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&lt;BR /&gt;JabberGuest: &lt;STRONG&gt;main_10.6.8.11&lt;/STRONG&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;From Lab:&lt;BR /&gt;[root@jabberguest ~]# openssl s_client -connect 10.x.x.x:5061 -cipher "EDH" | grep "Server Temp Key"&lt;BR /&gt;depth=0 CN = localhost.localdomain&lt;BR /&gt;verify error:num=18:self signed certificate&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=0 CN = localhost.localdomain&lt;BR /&gt;verify return:1&lt;BR /&gt;140461131990856:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:184:&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline; color: #ff0000;"&gt;&lt;EM&gt;Server Temp Key: DH, 768 bits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;____________________&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;LAB RECREATE w/ 10.6.9:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;JabberGuest: &lt;STRONG&gt;main_10.6.9.61&lt;/STRONG&gt; &lt;BR /&gt;&lt;BR /&gt;[root@jabberguest cdrom]# openssl s_client -connect 10.x.x.x:5061 -cipher "EDH" | grep "Server Temp Key"&lt;BR /&gt;depth=0 CN = localhost.localdomain&lt;BR /&gt;verify error:num=18:self signed certificate&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=0 CN = localhost.localdomain&lt;BR /&gt;verify return:1&lt;BR /&gt;140392344078152:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:184:&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline; color: #ff0000;"&gt;&lt;EM&gt;Server Temp Key: DH, 1024 bits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 19:05:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905131#M11086</guid>
      <dc:creator>Brian Pettis</dc:creator>
      <dc:date>2016-04-12T19:05:50Z</dc:date>
    </item>
    <item>
      <title>No problem. Good to hear that</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905132#M11087</link>
      <description>&lt;P&gt;No problem. Good to hear that everything can work fine.&lt;/P&gt;
&lt;P&gt;Btw,How do you do upgrade from 10.6.5.65 to 10.6.10.11? In our lab environment, the java version in Jabber Guest 10.6.10.11 is&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; "1.7.0_91", but in your environment ,it is 1.8.0-72.Have you do rpm upgrade manually?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 02:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905132#M11087</guid>
      <dc:creator>yjin2</dc:creator>
      <dc:date>2016-04-13T02:05:16Z</dc:date>
    </item>
    <item>
      <title>Ok, I just did it again to</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905133#M11088</link>
      <description>&lt;P&gt;Ok, I just did it again to test/verify.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Use the 10.6.5.65 for a blank install, upgraded to 10.6.10.11 with the upgrade iso file (bash upgrade) and now the server is on "1.7.0_91".&lt;/P&gt;
&lt;P&gt;Checking again the server I installed yesterday and this one is also on 1.7.0_91 (which is exactly the version you specified).&lt;/P&gt;
&lt;P&gt;Being totally confused I checked the version on my local machine which is, surprisingly 1.8.0_72".&lt;/P&gt;
&lt;P&gt;So I must have used the wrong console/terminal accidentally to distinguish the actual java version (reminds me to focus on one task at a time and not too much in parallel).&lt;/P&gt;
&lt;P&gt;Anyhow, the server I re-installed yesterday works fine with 8.7.2, so I'm ready to do the upgrade to 8.7.2 again on the upcoming weekend.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry for all the confusion and thanks for your help&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 07:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905133#M11088</guid>
      <dc:creator>WolSen000</dc:creator>
      <dc:date>2016-04-13T07:39:16Z</dc:date>
    </item>
    <item>
      <title>Hey Guys,</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905134#M11089</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;
&lt;P&gt;my Jabber Guest Server has a temp Key Size of 786 bit. My JG Version is 11. I reinstalled V11 2 times but the temp key does not change.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there an Option to Upgrade the Key manually?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 08:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905134#M11089</guid>
      <dc:creator>Sven Meyer</dc:creator>
      <dc:date>2017-02-03T08:05:19Z</dc:date>
    </item>
    <item>
      <title>Did you reboot your JG server</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905135#M11090</link>
      <description>&lt;P&gt;Did you reboot your JG server to make the configuration take effect?&lt;/P&gt;
&lt;P&gt;If you actually rebooted your server, what's the java version on that server? try command "java -version" in terminal, and let us know (may still use an old JDK version)&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2017 15:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-guest-doesn-t-work-with-expressway-8-7-2/m-p/2905135#M11090</guid>
      <dc:creator>niliu2</dc:creator>
      <dc:date>2017-02-05T15:26:09Z</dc:date>
    </item>
  </channel>
</rss>

