Configure Cisco Unified Communications Manager and Cisco IM and Presence certificates with the enterprise certificate authority
Cisco Unified Communications Manager (CUCM) and Cisco IM and Presence (CIMP) provide the ability to use multi-server certificates with Subject Alternative Names for tomcat, cup-xmpp, and cup-xmpp-ECDSA services. This topic describes certificate configuration using these recent feature enhancements. Multi-server certificates need only be configured on the CUCM and CIMP Publishers. Regardless of CIMP version, the cup service certificate is not multi-server and must be configured on each CIMP server in the cluster.
If your environment is not using multi-server certificates, you must use the Cisco Operating System Administration user interface on all of the CUCM and CIMP nodes to configure the Tomcat certificates. You must use the Cisco Operating System Administration interface on all of the CIMP nodes to configure the cup, cup-xmpp, and cup-xmpp-ECDSA certificates. The Cisco Tomcat service runs on both CUCM and CIMP servers. The cup, cup-xmpp, and cup-xmpp-ECDSA services only run on the CIMP servers.
When you configure the Presence service to communicate with CUCM and CIMP, you can configure the Cisco certificates to be signed by the enterprise certificate authority. You require the following certificates and certificate signing requests (CSR) when you want to configure the Presence service to communicate with the Cisco Unified Communications Manager and Cisco IM and Presence:
|
Service |
Certificates or CSRs |
|---|---|
|
Configure the Connect service only1 |
|
|
Configure the Presence service only1 |
|
1 If you configure both the Connect and Presence services, make sure that all of the required certificates or CSRs uploaded.