<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jaime, in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050281#M7601</link>
    <description>&lt;P&gt;Hi Jaime,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see I need public CA for the EXPe And to&amp;nbsp;go with private CA for all other servers including EXPc . But how this private signed certificate be trusted by mobile phones ? The trust store will affect only domain users on PCs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 05:48:39 GMT</pubDate>
    <dc:creator>Hythim Ali El Hadad</dc:creator>
    <dc:date>2017-05-24T05:48:39Z</dc:date>
    <item>
      <title>Certificate for Jabber with MRA</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050279#M7599</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have deployed jabber for windows and jabber for iphone with CUCM,CUC,IM&amp;amp;P, EXPc and EXPe&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see I'll generate CSR from all servers CUCM,CUC,IM&amp;amp;P tomcat and xmpp for IM&amp;amp;P and to sign it with a private CA and put it in he trust store to be trusted by our users. Where I'll upload the signed certificate . is this will be to tomcat also or tomcat-trust on each server ? also xmpp to be uploaded as xmpp also ?&lt;/P&gt;
&lt;P&gt;But how this will be trusted by the jabber for iphone ? or I must use public CA for this ?&lt;/P&gt;
&lt;P&gt;Also for EXPc and EXPe, which certificate will I generate knowing that I have generate CSR and sign it with private CA with client server template. So i think I can't regenrate another CSR. will I use the same generated signed CSR or only to sign the EXPe with client server template also with public CA to be trusted on both jabber windows and jabber mobile ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Finall question, Can I sign all certificates with private CA except EXPe . and to sign it with public CA ? so I'll get the generated CSR and to create the client server template on the public CA and to sign the certificate ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;please don't forget how jabber for iphone will trust the certificates signed by private CA or there is no way to sign it with public CA but the IT team tell it is too expensive .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;IT team tell me he can give me wildcard certificate but I tell him it still not supported. wish Cisco could support this soon&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 01:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050279#M7599</guid>
      <dc:creator>Hythim Ali El Hadad</dc:creator>
      <dc:date>2019-03-18T01:52:10Z</dc:date>
    </item>
    <item>
      <title>You upload the root CA to the</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050280#M7600</link>
      <description>&lt;P&gt;You upload the root CA to the z-trust store for each cert you're going to have signed, then upload the relevant server certificate.&lt;/P&gt;
&lt;P&gt;They won't be trusted, even if they're signed by a public CA, you need to deploy those certificates to the device's trust store in order to prevent any notification about the certificates.&lt;/P&gt;
&lt;P&gt;The certificate you want to have signed by a public CA, is the EXP-E, and it needs to have server/client authentication, that last bit is for BOTH expressways, the certificate will be rejected if those are not configured.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://docwiki.cisco.com/wiki/Certificates_FAQ&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 03:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050280#M7600</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2017-05-24T03:03:24Z</dc:date>
    </item>
    <item>
      <title>Hi Jaime,</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050281#M7601</link>
      <description>&lt;P&gt;Hi Jaime,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see I need public CA for the EXPe And to&amp;nbsp;go with private CA for all other servers including EXPc . But how this private signed certificate be trusted by mobile phones ? The trust store will affect only domain users on PCs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 05:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050281#M7601</guid>
      <dc:creator>Hythim Ali El Hadad</dc:creator>
      <dc:date>2017-05-24T05:48:39Z</dc:date>
    </item>
    <item>
      <title>That's why you need to use</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050282#M7602</link>
      <description>&lt;P&gt;That's why you need to use something like an MDM to push those certificates to the devices.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 16:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050282#M7602</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2017-05-24T16:05:15Z</dc:date>
    </item>
    <item>
      <title>What if we use public CA for</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050283#M7603</link>
      <description>&lt;P&gt;What if we use public CA for EXPe only and private CA for all other [cucm,cuc,im&amp;amp;p nd EXPc]&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Will I get certificate pop up when connecting from mobile for the internal servers ?&lt;/P&gt;
&lt;P&gt;Do you know if Cisco will support wildcard certificate in the near time ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 08:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050283#M7603</guid>
      <dc:creator>Hythim Ali El Hadad</dc:creator>
      <dc:date>2017-05-25T08:04:30Z</dc:date>
    </item>
    <item>
      <title>What if we use public CA for</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050284#M7604</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;What if we use public CA for EXPe only and private CA for all other [cucm,cuc,im&amp;amp;p nd EXPc]&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is exactly the design recommandation for certificates. Expressway-E uses Public CA and all internal servers use Private CA.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Will I get certificate pop up when connecting from mobile for the internal servers ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As long as mobile devices don't trust your Private CA, yes.&lt;/P&gt;
&lt;P&gt;Moreover, your deployment must be FULLY&amp;nbsp;using FQDNs to avoid the certificate popups, because trust is verified by cross checking the&amp;nbsp;FQDN shown in the certificate and the FQDN of the server to which you are trying to connect.&lt;/P&gt;
&lt;P&gt;To facilitate that, you should&amp;nbsp;work first on&amp;nbsp;Jabber for Desktop (since they are in the domain) so that it doesn't show popups internally. After that, extrapolate this to Mobile Users by importing the Private CA root certicate to the mobile devices.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But why insisting on that since the Certificate Verification will be checked only once as the&amp;nbsp;user logs in for the first time and afterwards it won't be popped up again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Do you know if Cisco will support wildcard certificate in the near time ?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- My personal opinion - I don't think it will be supported. The same problem exists in other Unified Communications solutions (eg Microsoft S4B), the wildcard certificate is not supported there too.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050284#M7604</guid>
      <dc:creator>ucanduc</dc:creator>
      <dc:date>2017-05-25T13:22:45Z</dc:date>
    </item>
    <item>
      <title>Bear in mind that you do not</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050285#M7605</link>
      <description>&lt;P&gt;Bear in mind that you do not only need the root CA on the devices, you need the &lt;STRONG&gt;server certificates&lt;/STRONG&gt; to be loaded in the devices to avoid the certificate warnings.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 13:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050285#M7605</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2017-05-25T13:30:08Z</dc:date>
    </item>
    <item>
      <title>In addition to the great</title>
      <link>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050286#M7606</link>
      <description>&lt;P&gt;In addition to the great answers here. its also considered to upload external certificates to call managers instead of internal signed certificates to avoid the certificate prompts in the mobile phones connecting through MRA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 21:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/certificate-for-jabber-with-mra/m-p/3050286#M7606</guid>
      <dc:creator>john michael marie rodriguez</dc:creator>
      <dc:date>2017-05-31T21:44:59Z</dc:date>
    </item>
  </channel>
</rss>

