08-31-2016 12:08 AM - edited 03-18-2019 06:19 AM
Hi Community,
I have generated CSR on the Expressway Core as well as in Expressway Edge and downloaded it for CA signing.
Once we obtain the signed certificates from CA, do i need to upload the two certificates (from Core and Edge) on both Expressways? So there will be two certificates needed to upload on each box?
Thank you.
08-31-2016 12:50 AM
Hello,
You need upload signed Core certificate to Expressway-Core and signed Edge certificate in Expressway-Edge.
Also you need apload root certificate from your CA in each Expressways in trusted CA section.
br Oleksandr
08-31-2016 03:33 AM
Hi Oleksandr,
Thanks for your reply.
The generated CSR from the Expressways already authorized by CA and provided me the files with .cer extension. I copied the files on my PC and converted the files to .pem so it can be used by Expressway base on the guide http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/config_guide/X8-7/Cisco-VCS-Certificate-Creation-and-Use-Deployment-Guide-X8-7.pdf on Appendix 3 using Microsoft Windows.
I'm trying to upload the PEM file on Maintenance > Security certificates > Server certificate but have error.
Any help? Also how to obtain the root certificate from CA?
Thank you
08-31-2016 03:56 AM
About error:
See: "Appendix 5: Enable AD CS to Issue "Client and Server" Certificates" in your manual. For sign expressway sertificates CA must use template with both Server and Client authentication.
About root sertificat (CA sertificat):
See: Managing the Trusted CA Certificate List (page 11)
br Oleksandr
08-31-2016 11:48 PM
Hi Oleksandr,
Thanks again for big help.
We managed to create new certification template using Web Server-Client and successfully uploaded on the Expressway.
But I'm little bit confused on the Root Certificate. We already uploaded the signed certificate, we need also to upload the Root Certificate right? How can we obtain the root certificate for us to upload on the Expressway? Is this the same .pem file we just uploaded earlier on Expressway under Maintenance > Security certificates > Server certificate? Then we need to upload it under Maintenance > Security certificates > Trusted CA certificate?
We used Windows Server 2012 as our CA.
Thank you for assistance.
09-01-2016 04:28 AM
Maintenance > Security certificates > Trusted CA certificate
Very nice guide here
See "Configuring the Trusted CA Certificate List on the VCS Expressway" section .
br Oleksandr
09-01-2016 06:11 AM
Thanks for the link.
does it apply on version X8.7? The guide is for X7.2.2 and X8.1. and for Webex Meeting Center.
We are deploying MRA in our case.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide