03-21-2016 05:00 AM - edited 03-19-2019 10:53 AM
I signed with local CA (win2012r2) for
Call Manager and IM&P tomcat cert (multi-server), IM&P cup, IM&P cup-xmpp certs on my lab.
But still Jabber for Windows client is keep asking to approve ccm cert. Client PC is on Domain so it has root cert.
I have one CCM 10.5.2.12901-1, one IM&P 10.5.2.22900-2.
I used Cisco Support Community's video as reference. (https://www.youtube.com/watch?v=FIqh3rSIUmA)
But I couldn't solve this issue.
Any suggestions?
Regards,
Baris .
Solved! Go to Solution.
03-21-2016 11:58 AM
OK, in the video I never mention that just following that procedure, will prevent you from getting that message, you only did half of the work, you signed your certs, NOW you need to distribute them to the machines.
Yes, the machine has the root cert, so it will trust the CUCM cert (once it's installed), but it doesn't actually have the cert for CUCM installed. If the machines do not have those certs pre-installed, they will need to install them as you login.
Cisco Jabber validates server certificates when authenticating to services. When attempting to establish secure connections, the services present Cisco Jabber with certificates. Cisco Jabber validates the presented certificate against what is in the client device's local certificate store. If the certificate is not in the certificate store, the certificate is deemed untrusted and Cisco Jabber prompts the user to accept or decline the certificate.
03-21-2016 11:58 AM
OK, in the video I never mention that just following that procedure, will prevent you from getting that message, you only did half of the work, you signed your certs, NOW you need to distribute them to the machines.
Yes, the machine has the root cert, so it will trust the CUCM cert (once it's installed), but it doesn't actually have the cert for CUCM installed. If the machines do not have those certs pre-installed, they will need to install them as you login.
Cisco Jabber validates server certificates when authenticating to services. When attempting to establish secure connections, the services present Cisco Jabber with certificates. Cisco Jabber validates the presented certificate against what is in the client device's local certificate store. If the certificate is not in the certificate store, the certificate is deemed untrusted and Cisco Jabber prompts the user to accept or decline the certificate.
03-22-2016 01:35 AM
Hello Jaime,
According to the this document actually I was expecting to not to prompted any certificate question.
So I have to populate CA signed certificates(tomcat, xmpp) to the domain clients, right ?
Regards,
Baris.
03-22-2016 07:17 AM
No, your understanding of the docs is wrong, not because you simply sign them, you're all done.
The process has not changed.
If you DO NOT want those accept/deny options when logging into Jabber, you need to make sure the certificates (explained in the doc I provided, and the one you pointed) ARE ALREADY in the machine TRUST STORE.
And I'm not talking about the root certificate, I mean the CUCM/IM&P/CUC/etc certificates, need to be in the LOCAL MACHINE TRUST STORE.
Did you read what I posted in my previous reply?????
03-22-2016 07:34 AM
Thanks Jaime for explaining. I just confused little bit. Now is ok.
Regards,
Baris.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide