cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2702
Views
15
Helpful
12
Replies

' HOST not Found ' - Security Error 'some' phones dont trust the server.

keanej
Level 3
Level 3

Recently upgraded to 12.5.1 and took the opportunity to replace the self signed certs with CA Signed certs.

For the Call Manager / Tomcat and IPSec , certs. Also added root ca/issueing ca to the trust store of these.

Everything (and Jabber) works perfect no cert errors anywhere - wonderfully smooth.

 

However.. an issue has arose.. a percentage of phones maybe 10%

- get 'host not found ' when you press the services and extension mobility.

The fault is the phone doesnt trust the server - probably due to the new cert- see below.

So Im thinking I have forgot to add the CA Root / Issueing to a store somewhere.. 

Question - how do I get the phones to trust the new cert ? but also - why some phones working and some not.

I cant find any common factors between the failing phones - difference models/ sites other models confgured the same at the same site - work perfect.

 

Is there a trust store somewhere that the phones import???

Any help appreacited.

 

James

 

 

ERR May 28 14:43:28.503400 (344-3945) SECUREAPP-No match found in trust list against the item
6494 ERR May 28 14:43:28.697857 (344-3946) SECUREAPP-filterOutCiphers:0 ret:1
 
ERR May 28 14:43:30.258548 (344-3945) SECUREAPP-TVS Cert Validation - provider returned NULL response
6503 ERR May 28 14:43:30.258609 (344-3945) SECUREAPP-Failed to validate cert using TVS
12 Replies 12

Jaime Valencia
Cisco Employee
Cisco Employee

I suggest you start by reading documentation related to ITL/TVS, that has been around since 8.x and anyone who manages a CUCM needs to be familiar with both concepts.

 

If you were able to upload your CA signed certificates to CUCM, all the necessary certificates are in the -trust stores.

Did you follow the proper documentation while uploading the new certificates and gave enough time in between them?

HTH

java

if this helps, please rate

Thanks for the response Jamie

 

I have replaced all the tomcat / cups/ certs and rebooted everything. I kinda presumed rebooting all the servers in sequence was the same thing.

Keep in mind - a lot of the phones are working perfect.

Could it be that some phones may have been powered off and didn't get the new trust list ?

Also some phones are failing on UCCX services , their tomcat is also now signed by the same local CA

 

I'll regenerate the TVS cert I think  and follow the procedure closely.

 

Using this guide - 

 

https://community.cisco.com/t5/collaboration-voice-and-video/cisco-uc-certificates-renewal-guide/ta-p/4077131

 

I'll let you know my progress !

 

Thanks

 

James

Followed the procedure EXACTLY - so TVS cert replaced across the cluster..restarted the services in the right order and waited till everything was done before moving on. Last but not least - rebooted all devices in the cluster (glup)

 

Still not working !!

 

Phone getting error - 

8238 ERR Jun 02 15:07:43.483659 (348-15866) SECUREAPP-No match found in trust list against the item

Getting annoying now..

 

So just to summarise - the phone loads, gets config - everything works perfect , but when they select the application 'extension mobility) they get 'host not found'

Service setup - XML Service 

with

https://HOSTNAMEGOOD:8443/emapp/EMAppServlet?device=#DEVICENAME#

Thanks

 

James 

can you remove the old  ITL/CTL by going to security setting on the phone and see if it resolve your issue. if the phone hold old it wont accept the new. 

 

You can find many contents about how to remove the CTL/ITL on google. 



Response Signature


You have to Remove the old  ITL files from Phones which has  issue. 

 

you can try the below tool to do it in bulk.

 

https://www.unifiedfx.com/products/phoneview-itl-delete

 

 



Response Signature


Nithin

 

Sorry - this isnt the correct solution

 

But thanks for responding.

Have you tried this on at least one phone before you wrote it off as not being the solution?

What you describe matches perfectly with phones loosing trust with the CM. This is controlled by two certificates, Callmanager and TVS. This is the reason for why these should never be renewed at the same time. At best there should be a period of a few weeks in between the renewal of these to let the phones get the new certificate.



Response Signature


 

Roger

 

Deffo not working - tried the security and factory reset

 

4790 ERR Jun 09 09:36:02.464823 (344-30586) SECUREAPP-Failed to validate cert using TVS
4791 INF Jun 09 09:36:02.466008 (29822-29950) JAVA-SSL session setup Cert Verification - Certificate validation helper plugin returned.
4792 ERR Jun 09 09:36:02.466063 (29822-29950) JAVA-SSL session setup Cert Verification - Certificate is invalid.
4793 DEB Jun 09 09:36:02.466084 (29822-29950) JAVA-SSL session setup Cert Verification - returning validation result = 0
4794 ERR Jun 09 09:36:02.466472 (29822-29950) JAVA-Sec SSL Connection - Handshake failed.

 

Please note - I only reset the TVS cert after this fault occurred

 

Thanks

 

James 

Scott Leport
Level 7
Level 7

Hi there,

 

Is EM the only thing which is affected? Have you tried updating the subscriptions under the IP phone service?

Also, not sure if you've seen this thread at all. It's quite a number of years old, but could be still applicable to your issue:

https://community.cisco.com/t5/ip-telephony-and-phones/host-not-found-extension-mobility-problem/td-p/1413533

 

All services impacted - setup another service and its the same

the old thread isnt relevant

 

This is 8841 on

 

Active Load ID:sip88xx.12-8-1-0101-482

.

 

But thanks

 

Just an update here - 

 

This fault it still happening ... its an odd one.

Basically have a Call Manager Certificate update- moved to company issued certs and loaded the root CAs into the trust stores... 

everything works perfect .. EXCEPT extension mobility - about 10-20% of the handsets have this 'host not found' error.

Its NOT an ITL reset. We have two models showing the error 8841 and 7945. You can do an ITL reset on the 7945 and 'security settings reset' on a 8841 - both dont fix the issue. Also tried factory reset.

Folks

 

Appreciate all the feedback  - one final cluster reset did the trick here. The issue was the CUCM publishers / subscribers need to be reloaded to activate the new certificate TVS configuration. Then the phones needs to be reset in the enterprise settings to pickup that TVS configuration.

The order of the reset & reboots is important. 

 

Thanks

 

James

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: