cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
729
Views
5
Helpful
4
Replies

CUCM Certificates with Exchange servers

navingolani
Level 1
Level 1

Hi,

Does any one know how to add certificates in CUCM 6.1?

Requirement: I need to add the secured SIP trunk between CUCM & Exchange server. If not wrong CUCM need to trust Exchange server so we need to add certificates to the CUCM

Regds,

Navin Golani

3 Accepted Solutions

Accepted Solutions

David Hailey
VIP Alumni
VIP Alumni

You add certs using the CM Platform, aka OS Administration web GUI.  Once logged in, it's Security > Certificate Management > Upload Certificate.

Hailey

Please rate helpful posts!

View solution in original post

The certificates you see uploaded are created during CUCM installation. They are the various self-signed certs for the components of the CUCM sub-systems. On the Exchange side, I believe you would need the root CA certificate which can be either self-signed (customer has their own CA) or from a 3rd-party.

Hailey

Please rate helpful posts!

View solution in original post

Do i need to upload CTL along with CA root certificate?

I referred to Security guide for OS admin guide, in it theyhave mentioned to upload Certificate , upload CTL & Upload Directory Trust Cert.

So do i need to do upload "Directory Trust " & CTL  ?

Also, in this document  says to download CTL from OS Admin > security > Certificate managemnet

But i believe we can download it from Plugin ?

IN CUCM 6.1, i do not see options for upoloading CTL or Directory trust. Only i found option for Upload Certificate, so how come its mentioned in document ?

View solution in original post

4 Replies 4

David Hailey
VIP Alumni
VIP Alumni

You add certs using the CM Platform, aka OS Administration web GUI.  Once logged in, it's Security > Certificate Management > Upload Certificate.

Hailey

Please rate helpful posts!

Thanks for the reply

I need to know is there any specific certificate need to be upload for creating the SIP trunk between CUCM & EXchange Server.

In my client CUCM server, i see couple of Certificates already uploaded  like CAPF Trust, callManager trust,ipsec & tomcat with particulay in ".PEM file " & " DER file"  . So which certificate i should be using for SIP trunk between CUCM & Exchange server. Where can i get it downloaded from?

The certificates you see uploaded are created during CUCM installation. They are the various self-signed certs for the components of the CUCM sub-systems. On the Exchange side, I believe you would need the root CA certificate which can be either self-signed (customer has their own CA) or from a 3rd-party.

Hailey

Please rate helpful posts!

Do i need to upload CTL along with CA root certificate?

I referred to Security guide for OS admin guide, in it theyhave mentioned to upload Certificate , upload CTL & Upload Directory Trust Cert.

So do i need to do upload "Directory Trust " & CTL  ?

Also, in this document  says to download CTL from OS Admin > security > Certificate managemnet

But i believe we can download it from Plugin ?

IN CUCM 6.1, i do not see options for upoloading CTL or Directory trust. Only i found option for Upload Certificate, so how come its mentioned in document ?