12-17-2021 09:49 PM
Hi All,
We have changed phone URL for home phone service/VPN gateway and later We have uploaded the ASA certificates on to phone-VPN trust certificates. We have added new certificates to VPN gateway certificates under VPN gateway configuration but not de-associated old certificates from VPN gateway.
Problem: When connected phone in the office to download the certs and returned home and it does not work.
1) Do we need to remove the old ASA certificates from VPN gateway certificates on cucm?
2)Do we need to re-generate the any of the certificates?
Please look into this.
Solved! Go to Solution.
12-20-2021 09:40 PM
1) Do we need to remove the old ASA certificates from VPN gateway certificates on cucm? Best Practice is to remove Unused certificates.
2)Do we need to re-generate the CAPF certificates after uploading ASA certificates on cucm to upload CAPF certs on ASA? There no such requirements mentioned in the document. You are uploading the ASA certificates to the CUCM Trust store.
01-18-2022 09:22 AM
The process i have followed to upload the ASA certificates is good, problem is from ASA side. They did fix it
12-18-2021 05:37 PM
Generate a certificate on the ASA when you set it up to support the VPN feature. Download the generated certificate to your PC or workstation and then upload it to Unified Communications Manager using the procedure in this section. Unified Communications Manager saves the certificate in the Phone-VPN-trust list.
The ASA sends this certificate during the SSL handshake, and the Cisco Unified IP Phone compares it against the values stored in the Phone-VPN-trust list.
If a Locally Significant Certificate (LSC) is installed on the Cisco Unified IP Phone, it will send its LSC by default.
To use device level certificate authentication, install the root MIC or CAPF certificate in the ASA, so that the Cisco Unified IP Phone are trusted.
12-19-2021 10:30 PM
Hi Nithin,
the process you mentioned above are completed already but still VPN phone is not working.
I have below queries, can you please look into them
1) Do we need to remove the old ASA certificates from VPN gateway certificates on cucm?
2)Do we need to re-generate the CAPF certificates after uploading ASA certificates on cucm to upload CAPF certs on ASA?
12-20-2021 11:22 AM
any views on above query?
12-20-2021 09:40 PM
1) Do we need to remove the old ASA certificates from VPN gateway certificates on cucm? Best Practice is to remove Unused certificates.
2)Do we need to re-generate the CAPF certificates after uploading ASA certificates on cucm to upload CAPF certs on ASA? There no such requirements mentioned in the document. You are uploading the ASA certificates to the CUCM Trust store.
12-20-2021 10:32 PM
Thanks Nitin,
I did remove the unused certs yesterday, we will test it on Thursday and I will post here the result
12-23-2021 06:58 AM
We have tested the phone and it is not working from home @Nithin Eluvathingal , are we missing anything here
01-18-2022 09:22 AM
The process i have followed to upload the ASA certificates is good, problem is from ASA side. They did fix it
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide