cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
418
Views
0
Helpful
4
Replies

CSR Certificate renewal in call manager and presence nodes

B@l@ji
Level 1
Level 1

I have question regarding the trust certificates. We have 5 nodes in our cluster, 3 cucm and 2 presence nodes.

All the tomcat certificates are internal CA signed. Tomcat cert is expiring in one of the presence nodes, we will submit a CSR and get CA signed. 

After getting the new certificate, do we need to upload the same certificate as "tomcat-trust" on other nodes?

Root and intermediate certificates are already present in all the nodes.

Can someone please explain how trust certificates work for CA signed certs?

 

1 Accepted Solution

Accepted Solutions

Look at this document for details on how to manage certificates in UC systems. Cisco UC Certificates Renewal Guide 



Response Signature


View solution in original post

4 Replies 4

 

 

if you are signing a tomcat cert you upload the signed certificate as tomcat certificate. 

Root/intermediate  certificate from the CA will be uploaded as the tomcat trust.

 

If you have the CA/intermediate in tomcat trust you don’t need to upload the CA again.

 

 



Response Signature


and all other nodes should have the CA/intermediate certs in their tomcat-trust?

 

You would upload these certificates on the Pub and it will distribute it to the other nodes in the cluster.



Response Signature


Look at this document for details on how to manage certificates in UC systems. Cisco UC Certificates Renewal Guide 



Response Signature


Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: