cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5681
Views
5
Helpful
6
Replies

CUCM and LDAP over SSL

john.galvin
Level 1
Level 1

I am trying to configure CUCM 8.03 to use LDAP synchronization and authentication with AD.  The AD server uses LDAP over SSL, so I downloaded the appropriate cert, and went to upload it as a directory trust cert into the CUCM OS Cert mgmt.

However, when I try to upload the cert, there is no directory trust type in the certificate name drop down box.  Do I need to do something to make the directory trust cert option appear, or is this some sort of bug?

Thanks

6 Replies 6

htluo
Level 9
Level 9

I would say it's a bug (don't have the bug number yet).

Open a TAC case and get the root access.  Then you may copy the cert to the file system directly.

Michael

http://htluo.blogspot.com

I noticed the same thing. We are getting ready to upload a Cert and the directory option isnt listed. We are on 8.0.3 as well. If you open a TAC case and it is a bug could you please post the BUG ID for when I open my TAC case?

Or if it is not a bug what the fix was?

daamador
Level 1
Level 1

Hi guys


Hope everyone is okay!


TAC engineer working on a case open up for this concern. Please allow me to address this problem to all of you reading this post


After consulting and researching, the bug that has been opened up for this is:


CSCtj75703

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtj75703



**This bug is still not visible to the public, but allow me to share with you that the only reason for this bug is that it was opened to correct
documentation problems on the Cisco Operating System Administration guide for all the CallManager 8.x versions (Security section)

On the Cisco documentation we can see the following:

Cisco Unified Communications Operating System Administration Guide, Release 8.0(2)
http://tools.cisco.com/squish/FdE6f

Upload a Directory Trust Certificate

Procedure

Step 1 Navigate to Security > Certificate Management.

The Certificate List window displays.

Step 2 Click Upload Certificate.

The Upload Certificate Trust List dialog box opens.

Step 3 Select directory-trust from the Certificate Name list.

Step 4 Enter the file to upload in the Upload File field.

Step 5 To upload the file, click the Upload File button.

Step 6 Log into Cisco Unified Serviceability.

Step 7 Navigate to Tools > Control Center - Feature Services.

Step 8 Restart the service Cisco Dirsync.

Step 9 Log in to the Cisco Unified Communications Operating System CLI as an administrator.

Step 10 To restart the Tomcat service, enter the command utils service restart Cisco Tomcat.

Step 11 After the services have been restarted, you can add the directory agreement for SSL.

****************************************************************

This bug was opened up to correct this problem on the Cisco documentation, the correct directory to upload the certificate will be : Tomcat-trust.

Hope this clears this concern.

Have a good one everyone

Daniel Amador
TAC Team
.:|:.:|:.  Cisco TAC Support Engineer
E-mail: daamador@cisco.com










Regards, Daniel Amador CCIE# 38898 (Voice) Cisco TAC Support Engineer

+5 for that, Daniel ! Thanks for the pointer to the bug.

- Sriram

wellsdavidj
Level 4
Level 4

So just to further clarify. The certificate needs to be uploaded as a tomcat-trust certificate and not a Directory-Trust cert? The bug is the documentation says Directory-Trust and it needs to say Tomcat-trust correct?

That's correct.