08-05-2014 08:03 PM - edited 03-17-2019 04:23 PM
Hi All UC Experts,
I'm using the Jabber at the inside and the outside.
At the outside, I generate the issued certs from public CA to the Expressway-C and Expressway-E. That still will prompt up the cert error when the user login the VPN-less Jabber at the outside. But the cert would be prompted the cert error one time, that mean if the user is the 1st time login and new install, so that would prompt cert one time, but it will not be happened as the second login.
As the inside, that is so uncomfortable. The internal Jabber would prompt many many certs' error. How many CUCM, IMP, UC, that would prompt the how many certs error. I checked some guide said I can change the related certs to sign by the public CA as below:
Server | Certificate |
---|---|
Cisco Unified Communications Manager IM and Presence | HTTP (Tomcat) XMPP |
Cisco Unified Communications Manager | HTTP (Tomcat) |
Cisco Unity Connection | HTTP (Tomcat) |
My CUCM, IMP, UC are self sign certs only. I can sign that out by public CA, but I'm afraid that will affect my production UC environment, including, internal IP-Phone, VPN IP-Phone, Jabber for Voice with ASA VPN (One click Anyconnect login), Cisco VCS ... Any ideas?
08-11-2014 10:12 AM
I want to know anyone have the experience change the tomcat certs as the production UC environment?
08-11-2014 11:57 PM
Hey,
this should not affect your phones or your VPN. They all use Callmanager/CAPF certificates.
Chris
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide