cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1683
Views
0
Helpful
1
Replies

SSL Certificate Installation for CUCM, UCCX & IM & Presence.

Quintin.Mayo
Level 2
Level 2

We have the following versions for the below appliances.

Call Manager version is 10.5.2.12901-1
UCCX version is 10.6.1.11001-31 (ES08-40)
IM & Presence version is 10.5.2.22900-2

 We want to install certificates on all devices, my questions are below.

Q1: When installing the certification on our Publisher and Subscriber, is a separate certificate required for each server or they use the same certificate?

Q2: Our the UCCX device, when loading a certificate is it automatically consumed by al of the components? or are there steps for applying to each?

1 Reply 1

Hi Quintin,

You can use multi-server(SAN) certificates for most of your servers. When you run a generate CSR requests you can select multi-server(SAN). on your CUCM/IM&P Cluster you would probably want to do this for Tomcat and Callmanager certificates. When you select the tomcat generate CSR you'll see it will add the IM&P servers aswell. Now you only need to do the cup-xmpp cert on the IM&P directly (and the s2s if you use site to site). When you upload the tomcat-trust / callmanager-trust and cup-xmpp-trust and tomcat/callmanager/cup-xmpp you only have to do this on the Publishers.

For UCCX you would want to sign the tomcat cert. You can upload the tomcat-trust on your primary but you will need to generate CSRs and install them on every node if you run a HA cluster.

So for your entire setup you will need about 4-5 separate signed certificates.

Hope this helps.