[cisco-voip] Field Notice from Cisco making Secure LDAP mandatory

Lelio Fulgenzi lelio at uoguelph.ca
Sun Feb 9 18:04:47 EST 2020


I believe we had to load two certs.

And, after loading certs, restart tomcat.



Sent from my iPhone

On Feb 9, 2020, at 5:23 PM, Matthew Loraditch <MLoraditch at heliontechnologies.com<mailto:MLoraditch at heliontechnologies.com>> wrote:

Interesting. Our root cert is and has been loaded, but I’m still using just the IPs so normally that would make the handshake fail.

Get Outlook for iOS<https://aka.ms/o0ukef>

Matthew Loraditch​
Sr. Network Engineer
p: 443.541.1518<tel:443.541.1518>
w: www.heliontechnologies.com<http://www.heliontechnologies.com/>        |      e: MLoraditch at heliontechnologies.com<mailto:MLoraditch at heliontechnologies.com>
<image367180.png><http://www.heliontechnologies.com/>
<image755198.png><https://facebook.com/heliontech>
<image389775.png><https://twitter.com/heliontech>
<image921900.png><https://www.linkedin.com/company/helion-technologies>
<image157220.jpg>
________________________________
From: Lelio Fulgenzi <lelio at uoguelph.ca<mailto:lelio at uoguelph.ca>>
Sent: Sunday, February 9, 2020 5:15:40 PM
To: Matthew Loraditch <MLoraditch at heliontechnologies.com<mailto:MLoraditch at heliontechnologies.com>>
Cc: James Buchanan <james.buchanan2 at gmail.com<mailto:james.buchanan2 at gmail.com>>; voyp list, cisco-voip (cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>) <cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>>
Subject: Re: [cisco-voip] Field Notice from Cisco making Secure LDAP mandatory


[EXTERNAL]


I couldn’t get secure ldap to work without loading the certificates from the AD servers. I also had more luck using the global catalog ports.

Sent from my iPhone

On Feb 9, 2020, at 5:05 PM, Matthew Loraditch <MLoraditch at heliontechnologies.com<mailto:MLoraditch at heliontechnologies.com>> wrote:

I was wondering if they were going to post anything as it’s very unclear if ldap over tls was the fix.

Apparently (and amen) it is. Did it on our office system last week to see if it would work without any certificate needs. It just worked and during a save it will instantly tell you if it worked or not.

Outside of the most regimented environments you should be able to just make the change. If it fails talk to your AD team as they would likely have something blocked or disabled.

Get Outlook for iOS<https://aka.ms/o0ukef>

Matthew Loraditch​
Sr. Network Engineer
p: 443.541.1518<tel:443.541.1518>
w: www.heliontechnologies.com<http://www.heliontechnologies.com/>        |      e: MLoraditch at heliontechnologies.com<mailto:MLoraditch at heliontechnologies.com>
<image502755.png><http://www.heliontechnologies.com/>
<image552534.png><https://facebook.com/heliontech>
<image068119.png><https://twitter.com/heliontech>
<image315640.png><https://www.linkedin.com/company/helion-technologies>
<image132003.jpg>
________________________________
From: cisco-voip <cisco-voip-bounces at puck.nether.net<mailto:cisco-voip-bounces at puck.nether.net>> on behalf of James Buchanan <james.buchanan2 at gmail.com<mailto:james.buchanan2 at gmail.com>>
Sent: Sunday, February 9, 2020 4:57:40 PM
To: voyp list, cisco-voip (cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>) <cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>>
Subject: [cisco-voip] Field Notice from Cisco making Secure LDAP mandatory


[EXTERNAL]


Hello folks,

I know you all needed some more work. I sure did! So here you are!

https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/trouble/12_5_1/fieldNotice/cucm_b_fn-secure-ldap-mandatory-ad.html

I'm interested in any early thoughts on other integrations--vCenter, ISE, VPN, TACACS, etc. I assume it applies across the board.

Thanks,

James

_______________________________________________
cisco-voip mailing list
cisco-voip at puck.nether.net<mailto:cisco-voip at puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image367180.png
Type: image/png
Size: 9409 bytes
Desc: image367180.png
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image755198.png
Type: image/png
Size: 431 bytes
Desc: image755198.png
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment-0001.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image389775.png
Type: image/png
Size: 561 bytes
Desc: image389775.png
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment-0002.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image921900.png
Type: image/png
Size: 444 bytes
Desc: image921900.png
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image157220.jpg
Type: image/jpeg
Size: 19523 bytes
Desc: image157220.jpg
URL: <https://puck.nether.net/pipermail/cisco-voip/attachments/20200209/5377185f/attachment.jpg>


More information about the cisco-voip mailing list