We created a new certificate template on our Microsoft SUB CA which includes both server and client EKU in the WebServer certificate.
The new VCS certificate certified with that template then uploaded without any warning on the VCS 8.1
Howerver I was still getting an error and the TLS trunk between the CUCM and the VCS was still failing. The VCS logs where showing a "Peer’s TLS certificate identity was unacceptable" error.
I tried putting the server name instead of the IP address inside of the "peer address" on the VCS Zone pointing to the CUCM PUB and SUB but it didn't make any difference.
As I guess the peer refers to the CUCM, I went ahead and changed both CUCM publisher and subscriber's callmanager certificate to certs certified by the same CA using the same server/client webserver template.
Yet it was still not working and it still showed the same error "Peer’s TLS certificate identity was unacceptable".
I finaly solved that last error by putting the server name instead of the IP address inside of the "peer address" on the VCS Zone pointing to the CUCM PUB and SUB
That was really a painful one. Would be helpful if Cisco's documentation was more precise on all the requirements and steps to get all that working.
Pls. make sure you uploaded RootCA certification with 'CallManager-trust', and generated CUCM cluster CSR select 'Certificate Purpose' with 'CallManager, at last for CUCM cluster certification to be uploaded(signed by CA) ensure select 'CallManager' for Certificate Purpose.