cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
577
Views
0
Helpful
1
Replies

UCM certificates

gonzalezel
Level 1
Level 1

We moved our voice environment to fully qualified domain names.  Since then I have multiple expired certificates callmanager-trust certficates where the common name is the host name.  However I have the new certificates where the common name is the fully qualified domain name that has a valid certificate.  Can I just delete the expired callmanager-trust certificates that are expired and keep the valid certs with the full fqdn. It seems like they do the same thing but I'm not very familiar with certificates. Thanks in advance.  For example:

Certificate Common Name Type Key Type Distribution Issued by Expiration
callmanager-trust admssub1 self-signed RSA admssub1 admssub1 1/30/2018
callmanager-trust admssub1.ad.johnson.com self-signed RSA admssub1.ad.johnson.com admssub1.ad.johnson.com 9/20/2020
1 Reply 1

GadgetFood
Level 1
Level 1
What version on CUCM are you running?
Did you regenerate the cluster?
We I updated UCM to FQDN I didnt have issue removing expired certificates I also did this during maintenance

Also see the below link which will give you so additional information on certificate regeneration and renewal
https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200199-CUCM-Certificate-Regeneration-Renewal-Pr.html#anc13
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: