12-21-2017 09:44 AM - edited 03-19-2019 01:01 PM
Hi gang,
We are upgrading from UCM 8.5 to 11.5.
As you probably know, this requires exporting and consolidating the TFTP certificates of both the new and old Call Managers. Then, you import the new, consolidated certificate back into the originating, old Call Manager. This is so that the VoIP endpoints will know to trust the new Call Manager.
The export and consolidation work fine with no errors. When I attempt to import the new, consolidated TFTP certificate back into the originating Call Manager, I get this error:
"org.bouncycastle.asn1.DERSequence cannot be cast to org.bouncycastle.asn1.ASN1OctetString"
This appears to be some sort of crypto incompatibility as described by this Cisco bug report:
https://quickview.cloudapps.cisco.com/quickview/bug/CSCuw80758
I *think* the solution is to upgrade the old, originating Call Manager to a new type of encryption standard, but I've no idea what or where to get it.
I'd appreciate any insight into this problem.
Thanks!
12-21-2017 09:59 AM
There are some bugs around this
Error Bulk cert import from 10.5.2.13900-2, or higher, to lower versions
CSCuy43181
You can do exactly the same thing manually, just download the certificates from one cluster, and upload them to the other cluster. That's really what the export/import/consolidate does.
12-21-2017 10:14 AM
This place never disappoints. Thanks for the rapid response.
So, simply upload the tftp cert. from the old, originating CM to the new one? If you confirm, I'll give it a shot.
12-21-2017 10:18 AM
That depends on what certificates you chose for the export, but yes, the idea is the same for all of them.
Export just sends them to a central repository, consolidate creates the bundle, and import gets the bundle and imports into the -trust stores. It's meant to simplify and avoid you downloading and importing individual certs, but you can still do that in case something fails.
12-21-2017 10:26 AM
Ok, looks like I had that backwards. I need the old CM to have the certificate from the new CM.
It's the TVS that I need to put onto the old CM.
Next question: Do I download the .PEM or the .DER format type?
12-21-2017 10:54 AM
Sorry, let me rewind a bit-
I'm attempting to consolidate TFTP certificates and place that on the old CM.
I am not seeing that certificate in the list of either Call Manager, so I am unsure which certificate in the list I should migrate to the old Call Manager.
The dialogue also asks for a root certificate and I'm unsure what to put into that field.
05-30-2018 10:33 PM
Hi R_Acuti,
You managed to resolve this issue ?
Can you please post steps you followed to resolve this ?
Thanks.
05-31-2018 04:04 AM
12-03-2018 07:56 AM
Original CUCM is using 9.1.2 and New CUCM is using 11.5.1 - we are migrating in phases and use Extension Mobility so the Blank ITL is not an option.
First, can I export from each of the CUCMs the TFTP certs to a centralized TFTP. Then run consolidate from the New 11.5.1 CUCM and then import these to Original 9.1.2 cluster. Reset TVS on the Original. Then move a group of phones to the New CUCM without an issue? Or are you saying it will need to be done manually.
Second, do these need imported on the TFTP servers?
Thanks!
12-03-2018 09:09 PM
12-04-2018 06:11 AM
12-04-2018 07:28 PM
12-05-2018 01:30 PM
We just tested with our DEV environment and worked like a champ. We have several TFTP servers so we downloaded the .PEM from both the TFTP servers in our "new" cluster and then loaded them as CallManager-Trust and Phone-SAST-Trust to the "original" cluster. 2 TFTP servers on new makes 2 .PEM files, then each of my original servers gets 4 trusts created. Thanks so much.
12-05-2018 05:58 PM - edited 12-05-2018 05:59 PM
Thanks for getting back and good to know that it worked fine. :) Good luck on your migration!
Please rate if it helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide