Download certificates from the Cisco Unified Communications Manager and Cisco IM and Presence servers into the BEMS Java keystore

You must import the following certificates from the Cisco Unified Communications Manager (CUCM) and Cisco IM and Presence (CIMP) servers. For multi-server certificates, only one certificate per cluster must be imported. If the certificate is not a multi-server certificate, a copy must be downloaded from each CUCM and CIMP server in a cluster and imported separately.
  • Tomcat.der
    • If your environment uses a multi-server certificate, a single copy of the certificate downloaded from the CUCM Publisher and CIMP Publisher servers is required.
    • If your environment does not use a multi-server certificate, a copy of the certificate downloaded from each CUCM and CIMP node is required.
  • Cup.der: A copy of the certificate downloaded from each CIMP node is required.
  • Cup-xmpp.pem and Cup-xmpp-ECDSA.pem
    • If using a multi-server certificate, a single copy of the certificate downloaded from the CIMP Publisher is required.
    • If not using a multi-server certificate, a copy of the certificate downloaded from each CIMP node is required.
  • Cup-ECDSA.der and Tomcat-ECDSA.der
    • If using a multi-server certificate, a single copy of the certificate downloaded from the CIMP Publisher is required.
    • If not using a multi-server certificate, a copy of the certificate downloaded from each CIMP node is required.
  1. Log on to the appropriate CUCM server.
  2. In the top-right Navigation drop-down list, click Cisco Unified OS Administration.
  3. Click Security > Certificate Management.
  4. Download the certificate named tomcat as a .der file.
  5. Log on to the appropriate CIMP server.
  6. In the top-right Navigation drop-down list, click Cisco Unified IM and Presence OS Administration.
  7. Click Security > Certificate Management.
  8. Download the cup-xmpp certificate and cup-xmpp-ECDSA certificate as a .pem file.
  9. Download the following .der files:
    • cup certificate
    • Cup-ECDSA
    • Tomcat-ECDSA
Import these certificates into the BEMS Java keystore. For instructions, see "Import the CA certificate into the Java certificate store" in the BEMS Core configuration content.