08-25-2014 11:50 AM - edited 03-15-2019 05:29 AM
Hi,
I have configured a Cisco Jabber with device security mode "Encrypted". Once I use this mode I am getting a error message in Cisco Jabber as:
"The certificate enrollment for secure computer calling has not been activated. Contact your system administrator."
The softphone feature is not working because of this.
Do you have any fix for this issue?
Thanks,
VJ
Solved! Go to Solution.
08-25-2014 03:56 PM
Is your CUCM cluster setup for mixed mode? If yes, what enrollment method did you chose as soft phones only support Authentication String. Only physical phones will have a MIC to do CAPF enrollment by.
09-16-2014 05:10 AM
This is expected behavior. The authentication string is a one-time shared secret to build a TLS tunnel during CAPF enrollment. The first client who entered the authentication code is given an X.509 certificate to use for subsequent CCM registration. If the device security profile is set to Authenticated or Encrypted, that X.509 certificate is required for the CSF device to register/work.
Unless you're using Windows roaming profiles or some other mechanism to make the user certificates portable between devices (e.g. smart cards??), you're stuck. IMO, tell the user they only get a laptop and can attach an external monitor when they're at the office.
08-25-2014 03:56 PM
Is your CUCM cluster setup for mixed mode? If yes, what enrollment method did you chose as soft phones only support Authentication String. Only physical phones will have a MIC to do CAPF enrollment by.
08-26-2014 05:27 AM
Hi Jonathan,
Thank you for your response. The CUCM cluster is setup in Mixed Mode. If you talking about Authentication Mode in Phone Security Profile for Cisco Jabber then it is set for "By Null String".
Thanks,
Vaijanath S.
08-26-2014 06:52 AM
Hi Jonathan,
Thank you for your help. The issues is now resolved after using the authentication string.
Thank you,
Vaijanath
08-26-2014 08:07 AM
Hi Jonathan,
As I have mentioned in earlier response that the jabber is now working by setting Authentication String. But the problem now I am facing is there is no simultaneous ring on desk phone and jabber. i.e. Jabber and desk phone are configured with same extension. when someone dials this extension it rings on desk phone only.
Thanks,
Vaijanath
09-12-2014 11:00 AM
Hi Jonathan,
I have one more issue with Cisco Jabber using authentication string. The authentication string works fine with the Jabber and softphone functionality is working.
Now the problem is: if the single user has two Jabber clients, one installed on laptop and second on desktop, the authentication string window is presented to the jabber client which logs in first. For example is I login from my laptop the window pops up to enter the authentication string. But now when I open the Jabber on my desktop it doesn't give me option to enter the authentication string and the softphone doesn't work.
Thanks,
Vaijanath
09-16-2014 05:10 AM
This is expected behavior. The authentication string is a one-time shared secret to build a TLS tunnel during CAPF enrollment. The first client who entered the authentication code is given an X.509 certificate to use for subsequent CCM registration. If the device security profile is set to Authenticated or Encrypted, that X.509 certificate is required for the CSF device to register/work.
Unless you're using Windows roaming profiles or some other mechanism to make the user certificates portable between devices (e.g. smart cards??), you're stuck. IMO, tell the user they only get a laptop and can attach an external monitor when they're at the office.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide