01-18-2023 06:52 AM
Hello - with the changes to Expressway X14.2 you now are required to have the ECDSA certificates signed. We ran into this because we upgraded from x14.0.7 to X14.2.2 and the neighbor zones would not come up because of self signed certificates. The TAC documents says we will need to get our TOMCAT and Callmanger ECDSA certificates signed by our internal CA which is trusted by Expressway. With that said we will be generating these as MULTI SAN so they cover all the CUCM and IMP nodes. If its just these 2 certificates for the CUCM and IMP nodes will this cause any issues with Unity connection, CER, or UCCX or do certificates need to be signed for those applications as well? The TAC article only references CUCM and the Expressway C.
This is the TAC article:
01-18-2023 11:18 AM
In your link you already would see that you need the certs for CUCM / IMP / Unity. The answers to your questions would be in there.
CER and UCCX have no connection with Expressway. Especially, when you only use MRA.
And no, there is no need to use ECDSA certs. You can also use classical RSA certs.
01-19-2023 10:32 PM
From a specific version of Expressway you do need to have both the ECDSA and RSA signed certificates or the certificate(s) of the CA that signed these in the trust store on the Expressway. At least if you’re following best practices and don’t want to go down the path of the workaround as outlined in the document.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide