06-23-2022 12:16 PM
We have upcoming Tomcat certificate renewal. So far it has been a pretty simple process, but this year the CA is saying please do not include 'OU' in the CSR generated as they are now issuing certificates without 'OU' field.
Now, when you generate a CSR in CuCM / CuC, there is no way to control what fields are included. So, if I send the CSR with 'OU' field and they CA sends the certificate without 'OU' and then I try to upload that new cert onto the server, will it be accepted or rejected.
I read somewhere in Cisco docs that 'OU field is optional for Cisco UC products' but my questions are -
06-23-2022 12:55 PM
06-23-2022 01:28 PM
this is not a MultiSan certificate. This is CA signed Tomcat Certificate for CuCM / CuC Publisher.
06-23-2022 03:34 PM
I don’t think that it would be a problem, but likely you’d won’t know until you try it. On your second question, yes you can upload new CA certs to the trust store. You can have as many different root CA certs as you’d like. However the OU information for your CM does not come from the information in the CA root certificate. That’s a configuration in CM that is made during initial installation.
06-24-2022 01:35 PM
There's an enhancement request for this:
F15522 - Make OU as non mandatory part of CSR
CSCwa75870
If the private key from the signed certificate matches that of the CSR, you should have no problem importing the certificate.
06-27-2022 07:09 AM
Thanks Jaime,
I found that enhancement bug. However that does not solve my issue as we would be able to upgrade the servers from 11.5.1 to 14.x is short period of time at our disposal.
However, your other statement is very interesting - to understand it clearly, if we get the certificate without OU from CA, and if the private key of the CSR and new cert match, then we should be good to install it on the servers. Please confirm if my understanding is good.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide