cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
0
Helpful
4
Replies

Third Party Certifica for encryption + CUCM 8.5

zarafa.nicolas
Level 1
Level 1

Hi all,

I want to use a third party PKI certificat to encrypt Calls on CUCM 8.5.

Please , would you mind to  send me what steps that i have to follow to do this configuration?

Also, i want know if there is any issue to do this configuration on a production environnement ?

Thanks in advance

Nicalas

4 Replies 4

Zaid Salama
Cisco Employee
Cisco Employee

hey Nikolas,

check the link below, it includes the procedure for the 3rd party certicates on CUCM.

http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/cucos/5_1_1/iptpch6.html#wp1046223

Regards

refram
Level 3
Level 3

Why are you planning on using 3rd party certificates for encrypting calls?

  Yes refram,  I want use the third party certifcat for calls encryption  ( the customent has its PKI SERVER).

thanks in advance

While it's possible to upload a 3rd party certificate to CUCM, as far as I know the only way to do what you want to do is use the CTL client and get a pair of security USB keys from Cisco.  At any rate the keys are relatively inexpensive and if you get two pairs of them you can test encryption in a lab with one pair, and then use the other pair to do a limited deployment in production, and finally build out from there.  It's perfectly secure, good enough for the DOD so it should be good enough for about anyone.  The big problem with the keys is that they can be hard to come by.  It may be easier now, but last year it took a lot of research and a lot of begging to get them.   

Just remember that for real security you also have to encrypt calls and signaling to and from the voice gateways, as well as calls that may use any hardware conferencing devices.

There are, what I think, are three good write-ups on the subject.

http://www.netcraftsmen.net/resources/blogs/configuring-calling-encryption-between-cisco-ip-phones.html?blogger=Paul+Smith

http://www.netcraftsmen.net/resources/blogs/configuring-a-secure-voice-gateway.html?blogger=Paul+Smith

http://www.netcraftsmen.net/resources/blogs/configuring-secure-hardware-conferencing.html

It's kind of a pain and will take a while to do, but it's pretty cool once you get it working.

Good Luck,

Refram