CUMC7.1 - how the certification works

Unanswered Question
Apr 12th, 2010
User Badges:

Hi,


I installed CUMC on Nokia E61i with the environment,

-CUCM7.1.3

-CUMA7.1.3

-ASA8.0.4 (proxy server), static NAT between public IP@ and CUMA IP@

-public domain name maps to the public IP@

-CUMC accessing the ASA public IP@ which is static mapped to CUMA IP@ via public domain name

-import certificate from ASA into CUMA

-import certificate from CUMA into ASA


I didn't install public certificate (ex, Verisign) and CUMC gets the message periodically "This site has sent on untrusted certification. Continue anyway?" and the CUMC features all work okay if I select "continue"


Q1) is the behavior manually replying with "continue" whenever get the certificate message on CUMC okay to assure the CUMC operation before purchase the public certificate from Verisign or something caveat on this behavior?


Q2) if I install public certification from Verisign, no longer the certification message on CUMC?


Advise please,

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Naoufal KERBOUTE Mon, 05/17/2010 - 07:17
User Badges:

Hi,


I'm working on the same envirement like you, but i've got a message on my IPhone "Invalid Certificate (1024),

Could you please explain how did you import certificate to cuma and vice versa.


Regards


Naoufal

htluo Mon, 05/17/2010 - 13:13
User Badges:
  • Red, 2250 points or more

Q1) is the behavior manually replying with "continue" whenever get  the certificate message on CUMC okay to assure the CUMC operation before  purchase the public certificate from Verisign or something caveat on  this behavior?


Answer: Yes.  It's ok to "continue".  Every feature should work.


Q2)  if I install public certification from Verisign, no longer the  certification message on CUMC?


Answer: the point is, your mobile needs to trust the certificate presented by ASA.  Cisco recommend Verisign because it was "pre-installed" on most of the cell phones.  If the certificate presented by ASA was not trusted by mobile phone, you need to install the cert manually on mobile phone.  (check with your mobile phone vendor for details)


Michael

http://htluo.blogspot.com

Actions

This Discussion