02-09-2025 04:41 AM
Hello, FYI this is a lab environment, I have a certificate based trunk setup. I followed the Webex guide to setting up a certificate based trunk (LGW). My question revolves around the certificate itself. It says that Webex only accepts "WEBEX approved CA certificates only". I have an internal ADCS that I use to sign my Cube certificate. I install the CA cert and the CA signed router cert. In the guide it also tells me to run the command:
crypto pki trustpool import clean url https://www.cisco.com/security/pki/trs/ios_core.p7b
After this I followed the guide and completed setup I get the following:
02-09-2025 06:33 AM
No you can not use an internal CA. You need to use an external public CA that is in the list of approved CAs for Webex.
02-09-2025 06:36 AM
This article lists the approved CAs. https://help.webex.com/en-us/article/WBX9000008850/What-Root-Certificate-Authorities-are-Supported-for-Calls-to-Cisco-Webex-Audioand-Video-Platforms?
02-09-2025 10:27 AM - edited 02-09-2025 10:28 AM
Thank you so much for replying so quickly. My issue is finding the CA servers from that list that will sign my router CSR and provide those CA signed certificates. Maybe I am missing an important step in understanding how to put the provided bundles to use. Do I download the provided CA bundles before I run the pki enroll process. Its just pretty ambiguous to me because I have not been able to get it to work. I'm sure once it actually works for me it will click lol.
02-09-2025 11:49 AM
This article might help you. IOS CA - basic deployment; certificate enrollment and signing process.
02-09-2025 01:12 PM
Thank you again for responding!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide