cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
219
Views
0
Helpful
2
Replies

Expressway X14.2.2 CUCM neighbor zones

shleets
Level 1
Level 1

Hello - with the changes to Expressway X14.2 you now are required to have the ECDSA certificates signed.  We ran into this because we upgraded from x14.0.7 to X14.2.2 and the neighbor zones would not come up because of self signed certificates.  The TAC documents says we will need to get our TOMCAT and Callmanger ECDSA certificates signed by our internal CA which is trusted by Expressway.  With that said we will be generating these as MULTI SAN so they cover all the CUCM and IMP nodes.  If its just these 2 certificates for the CUCM and IMP nodes will this cause any issues with Unity connection, CER, or UCCX or do certificates need to be signed for those applications as well?  The TAC article only references CUCM and the Expressway C.

This is the TAC article:

https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/218018-troubleshoot-expressway-traffic-server-c.html

 

2 Replies 2

b.winter
VIP
VIP

In your link you already would see that you need the certs for CUCM / IMP / Unity. The answers to your questions would be in there.

CER and UCCX have no connection with Expressway. Especially, when you only use MRA.
And no, there is no need to use ECDSA certs. You can also use classical RSA certs.

From a specific version of Expressway you do need to have both the ECDSA and RSA signed certificates or the certificate(s) of the CA that signed these in the trust store on the Expressway. At least if you’re following best practices and don’t want to go down the path of the workaround as outlined in the document.



Response Signature


Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: