Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

SSL Certificate Installation for CUCM, UCCX & IM & Presence.

We have the following versions for the below appliances.

Call Manager version is 10.5.2.12901-1
UCCX version is 10.6.1.11001-31 (ES08-40)
IM & Presence version is 10.5.2.22900-2

 We want to install certificates on all devices, my questions are below.

Q1: When installing the certification on our Publisher and Subscriber, is a separate certificate required for each server or they use the same certificate?

Q2: Our the UCCX device, when loading a certificate is it automatically consumed by al of the components? or are there steps for applying to each?

1 REPLY

Hi Quintin,

Hi Quintin,

You can use multi-server(SAN) certificates for most of your servers. When you run a generate CSR requests you can select multi-server(SAN). on your CUCM/IM&P Cluster you would probably want to do this for Tomcat and Callmanager certificates. When you select the tomcat generate CSR you'll see it will add the IM&P servers aswell. Now you only need to do the cup-xmpp cert on the IM&P directly (and the s2s if you use site to site). When you upload the tomcat-trust / callmanager-trust and cup-xmpp-trust and tomcat/callmanager/cup-xmpp you only have to do this on the Publishers.

For UCCX you would want to sign the tomcat cert. You can upload the tomcat-trust on your primary but you will need to generate CSRs and install them on every node if you run a HA cluster.

So for your entire setup you will need about 4-5 separate signed certificates.

Hope this helps.

93
Views
0
Helpful
1
Replies
CreatePlease login to create content