cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3464
Views
40
Helpful
8
Replies

Installing CA Signed Tomcat Certificate on CUCM

aniket0422
Level 1
Level 1

 

Hi Team,

 

I have installed CA signed Tomcat Certificate by following Jaime Sir's Video on CUCM.

 

When I try to log into CUCM using FQDN i can see "Secure Connection" mark.

 

But when i try to log into same CUCM using IP address or only Hostname i still get " Your connection is not secure". 

 

Am i missing something. Are there any Pre-requisites with respect to domain and DNS ?
3 Accepted Solutions

Accepted Solutions

No public ca will touch that CSR for sure.
If you local one doesn’t have a problem with it you can always try if should work however why bother with it. Just make yourself some book marks. However those other names would need to be in your SANs field not CN

View solution in original post

no if requesting a certificate from a public CA,  the CN can only contain ONE name,  either domain name or FQDN. the other names must be specified in the SAN 

depends on the CA if only names within the same domain as the CN are accepted.

View solution in original post

Hi Aniket

the common name (CN) is the DNS host name of the CUCM, other addresses go in the SAN (Subject Alternate Names), this guide will better explain what you need from a CUCM perspective >> https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/115957-high-level-view-ca-00.html#commonsubject

feel free to go through the whole TechNote

Hope this helps - please rate if helpful

View solution in original post

8 Replies 8

pieterh
VIP
VIP
look at your certificate!
there must be a match between names in the certificate and the url that you use to access the CUCM
so either you need multiple certificates (hostname, FQDN, IP-address) or you need a single (FQDN) certificate that specifies IP address and shortname as SAN (subject alternative name / alias)

ali.yusuf
Level 1
Level 1
HI Aniket -

unfortunately ive not seen this Video, but Generally speaking, certificates are created for the hostname/FQDN of the server in this case the CUCM, as a result if you browse to the IP address it does not recognise it and will show you an error, you can test this by visiting https://www.google.com and thereafter https://64.233.162.105 you will see a difference. in theory you can add IP address in the SAN but this is not normal practice

Hope this helps - please rate if helpful

R0g22
Cisco Employee
Cisco Employee
If your certificate has an FQDN anything other than that i.e. just a hostname or an IP address will cause the untrusted connection since your client i.e the PC or rather I should say the browser won't trust the certificate. What you see is expected.

 

What if I put Hostname, IP Address and FQDN while generating CSR from CUCM.

 

Capture.JPG

 

 

No public ca will touch that CSR for sure.
If you local one doesn’t have a problem with it you can always try if should work however why bother with it. Just make yourself some book marks. However those other names would need to be in your SANs field not CN

no if requesting a certificate from a public CA,  the CN can only contain ONE name,  either domain name or FQDN. the other names must be specified in the SAN 

depends on the CA if only names within the same domain as the CN are accepted.

Hi Aniket

the common name (CN) is the DNS host name of the CUCM, other addresses go in the SAN (Subject Alternate Names), this guide will better explain what you need from a CUCM perspective >> https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/115957-high-level-view-ca-00.html#commonsubject

feel free to go through the whole TechNote

Hope this helps - please rate if helpful