08-16-2011 06:54 PM - edited 03-16-2019 06:31 AM
Hi all,
I want to use a third party PKI certificat to encrypt Calls on CUCM 8.5.
Please , would you mind to send me what steps that i have to follow to do this configuration?
Also, i want know if there is any issue to do this configuration on a production environnement ?
Thanks in advance
Nicalas
08-17-2011 06:30 AM
hey Nikolas,
check the link below, it includes the procedure for the 3rd party certicates on CUCM.
http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/cucos/5_1_1/iptpch6.html#wp1046223
Regards
08-17-2011 06:54 AM
Why are you planning on using 3rd party certificates for encrypting calls?
08-17-2011 09:41 AM
Yes refram, I want use the third party certifcat for calls encryption ( the customent has its PKI SERVER).
thanks in advance
08-17-2011 10:18 AM
While it's possible to upload a 3rd party certificate to CUCM, as far as I know the only way to do what you want to do is use the CTL client and get a pair of security USB keys from Cisco. At any rate the keys are relatively inexpensive and if you get two pairs of them you can test encryption in a lab with one pair, and then use the other pair to do a limited deployment in production, and finally build out from there. It's perfectly secure, good enough for the DOD so it should be good enough for about anyone. The big problem with the keys is that they can be hard to come by. It may be easier now, but last year it took a lot of research and a lot of begging to get them.
Just remember that for real security you also have to encrypt calls and signaling to and from the voice gateways, as well as calls that may use any hardware conferencing devices.
There are, what I think, are three good write-ups on the subject.
http://www.netcraftsmen.net/resources/blogs/configuring-secure-hardware-conferencing.html
It's kind of a pain and will take a while to do, but it's pretty cool once you get it working.
Good Luck,
Refram
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide