cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1917
Views
5
Helpful
12
Replies

Add Ip address on CUCM SAN certificate

nicanor00
Level 1
Level 1

Hi

I have CUCM 12.5 and my CA

For internal purpose, I need to add IP address as SAN on the certificat

 

How can I do it ?

 

12 Replies 12

You can add the IP address in CN field. 

output of csr decoder(online tools) to see the csr details

 

Screenshot 2021-04-26 at 1.01.04 PM.png

On CUCM while generating csr I added common name As ip address

Screenshot 2021-04-26 at 12.57.51 PM.png



Response Signature


nicanor00
Level 1
Level 1

Hi and thanks for your answer

 

It look like we dont have the same interface, anyway we have the same menu

I need to generate CSR for  : tomcat, call manager and IPsec

I have CUCM and IM&P (suscriber and publicher on each)

the CUCM name is ABCD.tomato.com

the domain name is tomato.com

The ip adress of the CUCM is 192.168.0.1

My CA accept only one unique common name, so  it can not accept 2 CSR with the same common name

 

When I put ip adress of the CUCM in the SAN, it doenst accept

 

I my situation, Please how Can I add ip adress in the SAN ?

Thanks

 

 

 

 

 

We both have same interface. Add the IP in common name and add FQDN on SAN



Response Signature


Great answer by Nithin above. Just remember that you can add more than one SAN separated by a comma. So if your Signing Authority returns the Certificate with the top level domain or www on the front(GoDaddy), you can add more SAN's in that field.

Please rate if this helps.

Hi all

Thanks for your answer

I need to generate 3 CSR  : tomcat, ipsec and call manager

My CA cannot accept 2 CSR with the same common name (same cucm ip adress) for all those 3 CSR

 

So please how can I manage it ?

 

 

I never seen such an issue  that My CA cannot accept 2 CSR with the same common name. I have renewed CSR for all the  services you mentioned, and my server team was able to sign it using Microsoft CA for all individual CSR. 

 

 

 



Response Signature


Vinod16
Level 1
Level 1

@Nithin Eluvathingal  Hi nithin,

I am adding IP in CN and IN SAN - parent domain  ( domain , FQDN cucm) but getting error while generating Cert.

Invalid Parent Domain. Please use a standard domain format.

 

CUCM 12.5

You cannot enter an IP address in the field parent domain as a SAN entry. As already written by @Nithin Eluvathingal 

You cant add the IP on the parent domain. 



Response Signature


Like I'm also having the same problem. I also tried to create a CSR with Distribution as "Multi-server" but don't know how to add IP addresses to the SAN field. Can you share with me how to do it properly, please?

If you would read carefully, then your question would be unnecessary:
"You cannot enter an IP address in the field parent domain as a SAN entry."

As @b.winter and @Nithin Eluvathingal already have written you cannot add IP addresses to the CSR. It is not intended to work as it is not a proper thing to do in a certificate. It should only contain FQDNs and DNS domains.



Response Signature