<div dir="ltr">To Dennis' point you don't have to put <a name="14e921e671a51b20__MailEndCompose" style="color:rgb(34,34,34);font-size:12.8000001907349px"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">DNS=mycollab.com in the SAN. There is an alternative to use </span></a><a name="14e921e671a51b20__MailEndCompose" style="color:rgb(34,34,34);font-size:12.8000001907349px"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">DNS=collab-edge.mycollab.com</span></a><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6666669845581px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6666669845581px"><a href="http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-5/Mobile-Remote-Access-via-Expressway-Deployment-Guide-X8-5.pdf">http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-5/Mobile-Remote-Access-via-Expressway-Deployment-Guide-X8-5.pdf</a></span></font></div><div><div><a name="14e921e671a51b20__MailEndCompose" style="color:rgb(34,34,34);font-size:12.8000001907349px"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><br></span></a></div><div><a name="14e921e671a51b20__MailEndCompose" style="color:rgb(34,34,34);font-size:12.8000001907349px"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><img src="cid:ii_14e93180d263c498" alt="Inline image 1" width="521" height="171"><br></span></a></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jul 15, 2015 at 2:16 PM, Heim, Dennis <span dir="ltr"><<a href="mailto:Dennis.Heim@wwt.com" target="_blank">Dennis.Heim@wwt.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><a name="14e92ef0284acc7a__MailEndCompose"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">If you have not seen the Cisco Live session on collab security I would definitely recommend it. It had some good discussion on certificates.
Based on that Wildcard certs will never be supported on CUCM and the like and are frowned upon within the security community.
<u></u><u></u></span></a></p><span class="">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal" style="text-autospace:none"><b><span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:black">Dennis Heim | Emerging Technology Architect (Collaboration)</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><u></u><u></u></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:black">World Wide Technology, Inc. | <a href="tel:%2B1%20314-212-1814" value="+13142121814" target="_blank">+1 314-212-1814</a><u></u><u></u></span></p>
<p class="MsoNormal" style="text-autospace:none"><a href="https://twitter.com/CollabSensei" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;text-decoration:none"><img border="0" width="124" height="25" src="cid:image001.png@01D0BF08.AAC53980" alt="twitter"></span></a><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><u></u><u></u></span></p>
<p class="MsoNormal" style="text-autospace:none"><a><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d;text-decoration:none"><img border="0" width="95" height="28" src="cid:image002.png@01D0BF08.AAC53980" alt="chat"></span></a><a href="tel:+13142121814" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d;text-decoration:none"><img border="0" width="95" height="28" src="cid:image003.png@01D0BF08.AAC53980" alt="Phone"></span></a><a><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d;text-decoration:none"><img border="0" width="95" height="28" src="cid:image004.png@01D0BF08.AAC53980" alt="video"></span></a><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.0pt;font-family:"Calibri",sans-serif;color:#1f497d">“There is a fine line between Wrong and Visionary. Unfortunately, you have to be a visionary to see it." – Sheldon Cooper<u></u><u></u></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><a href="https://wwt.webex.com/meet/dennis.heim" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#0563c1">Click here to join me in my Collaboration Meeting Room</span></a><u><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#0563c1"><u></u><u></u></span></u></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
</span><div>
<div style="border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> Eric Pedersen [mailto:<a href="mailto:PedersenE@bennettjones.com" target="_blank">PedersenE@bennettjones.com</a>]
<br>
<b>Sent:</b> Wednesday, July 15, 2015 12:51 PM<br>
<b>To:</b> Anthony Holloway; Heim, Dennis; Ian Anderson; NateCCIE; Cisco VOIP<br>
<b>Subject:</b> RE: [cisco-voip] Digicert Wildcard certificates<u></u><u></u></span></p>
</div>
</div><div><div class="h5">
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Good point. I spoke too soon: we use wildcard certificates on VCS-E and WebEx Meeting Server only. IIRC VCS officially doesn’t support wildcard certificates either
but everything seems to work provided the hostnames are configured as SANs. CUCM might be the same with the multi-server certificate but I haven’t tried.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> Anthony Holloway [<a href="mailto:avholloway+cisco-voip@gmail.com" target="_blank">mailto:avholloway+cisco-voip@gmail.com</a>]
<br>
<b>Sent:</b> 15 July 2015 10:43 AM<br>
<b>To:</b> Eric Pedersen; Heim, Dennis; Ian Anderson; NateCCIE; Cisco VOIP<br>
<b>Subject:</b> Re: [cisco-voip] Digicert Wildcard certificates<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">I'm a little confused here. According to this article: <a href="http://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/115957-high-level-view-ca-00.html#wildcard" target="_blank">http://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/115957-high-level-view-ca-00.html#wildcard</a>,
and this defect ID: <a href="https://tools.cisco.com/bugsearch/bug/CSCta14114/" target="_blank">https://tools.cisco.com/bugsearch/bug/CSCta14114/</a>, wild card certs are not supported. Are we talking about the same thing here?<u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Wed, Jul 15, 2015 at 10:08 AM Eric Pedersen <<a href="mailto:PedersenE@bennettjones.com" target="_blank">PedersenE@bennettjones.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Digicert lets you put your domain and subdomains of any level as SANs. It’s great! They even generated
a duplicate certificate for me with a different root CA that was supported with WebEx enabled Telepresence. We use their wildcard certificates on all of our UC servers.</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span><u></u><u></u></p>
<div>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"> cisco-voip [mailto:<a href="mailto:cisco-voip-bounces@puck.nether.net" target="_blank">cisco-voip-bounces@puck.nether.net</a>]
<b>On Behalf Of </b>Heim, Dennis<br>
<b>Sent:</b> 15 July 2015 8:28 AM<br>
<b>To:</b> Ian Anderson; NateCCIE; Cisco VOIP</span><u></u><u></u></p>
</div>
</div>
</div>
</div>
<div>
<div>
<div>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif"><br>
<b>Subject:</b> Re: [cisco-voip] Digicert Wildcard certificates</span><u></u><u></u></p>
</div>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"><a name="14e92ef0284acc7a_msg-f:1506775327391252231__MailEndCompos"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I’ve found the hardest thing to find a cert providers
that likes putting the domain as a san such as DNS=mycollab.com. Has anyone found any providers that are kosher with that? From one of the Cisco Live sessions, I was told this is needed for service discovery to function properly.</span></a><u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<b><span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:black">Dennis Heim | Emerging Technology Architect (Collaboration)</span></b><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:black">World Wide Technology, Inc. | <a href="tel:%2B1%20314-212-1814" value="+13142121814" target="_blank">+1 314-212-1814</a></span><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<a href="https://twitter.com/CollabSensei" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;text-decoration:none"><img border="0" width="124" height="25" src="cid:image001.png@01D0BF08.AAC53980" alt="twitter"></span></a><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><img border="0" width="95" height="28" src="cid:image002.png@01D0BF08.AAC53980" alt="chat"></span><a href="tel:+13142121814" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d;text-decoration:none"><img border="0" width="95" height="28" src="cid:image003.png@01D0BF08.AAC53980" alt="Phone"></span></a><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><img border="0" width="95" height="28" src="cid:image004.png@01D0BF08.AAC53980" alt="video"></span><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<span style="font-size:8.0pt;font-family:"Calibri",sans-serif;color:#1f497d">“There is a fine line between Wrong and Visionary. Unfortunately, you have to be a visionary to see it." – Sheldon Cooper</span><u></u><u></u></p>
<p class="MsoNormal" style="text-autospace:none">
<span style="font-size:8.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span><u></u><u></u></p>
<p class="MsoNormal"><a href="https://wwt.webex.com/meet/dennis.heim" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#0563c1">Click here to join me in my Collaboration
Meeting Room</span></a><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span><u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> cisco-voip [<a href="mailto:cisco-voip-bounces@puck.nether.net" target="_blank">mailto:cisco-voip-bounces@puck.nether.net</a>]
<b>On Behalf Of </b>Ian Anderson</span><u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><br>
<b>Sent:</b> Wednesday, July 15, 2015 10:18 AM<br>
<b>To:</b> NateCCIE; Cisco VOIP<br>
<b>Subject:</b> Re: [cisco-voip] Digicert Wildcard certificates</span><u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<p class="MsoNormal">On 15 July 2015 at 15:02, NateCCIE <<a href="mailto:nateccie@gmail.com" target="_blank">nateccie@gmail.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal">Did you put all of your SANs in the digicert page?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:#1f497d">z</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">I have this working on all of my expressway installs. <u></u><u></u></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal">Hi Nate, <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks for the quick response, just for preservation in the archives for future posterity and confirmation that digicert seems fine despite the warnings in the manuals, it seemed
I was running into 2 separate issues.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">1) I had uploaded the intermediate cert, but needed to manually download and upload the root CA<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">2) That then got me past the TLS error, only to find that I had fat-fingered the hostname in the SAN field :-(<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Cheers<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Ian <u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<p class="MsoNormal"><br>
<br>
The contents of this message may contain confidential and/or privileged subject matter. If this message has been received in error, please contact the sender and delete all copies. Like other forms of communication, e-mail communications may be vulnerable to
interception by unauthorized parties. If you do not wish us to communicate with you by e-mail, please notify us at your earliest convenience. In the absence of such notification, your consent is assumed. Should you choose to allow us to communicate by e-mail,
we will not take any additional security measures (such as encryption) unless specifically requested.
<br>
<br>
If you no longer wish to receive commercial messages, you can unsubscribe by accessing this link:
<a href="http://www.bennettjones.com/unsubscribe" target="_blank">http://www.bennettjones.com/unsubscribe</a>
<u></u><u></u></p>
</div>
<p class="MsoNormal">_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net" target="_blank">cisco-voip@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/cisco-voip" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><u></u><u></u></p>
</blockquote>
</div>
<p class="MsoNormal"><br>
<br>
The contents of this message may contain confidential and/or privileged subject matter. If this message has been received in error, please contact the sender and delete all copies. Like other forms of communication, e-mail communications may be vulnerable to
interception by unauthorized parties. If you do not wish us to communicate with you by e-mail, please notify us at your earliest convenience. In the absence of such notification, your consent is assumed. Should you choose to allow us to communicate by e-mail,
we will not take any additional security measures (such as encryption) unless specifically requested.
<br>
<br>
If you no longer wish to receive commercial messages, you can unsubscribe by accessing this link:
<a href="http://www.bennettjones.com/unsubscribe" target="_blank">http://www.bennettjones.com/unsubscribe</a>
<u></u><u></u></p>
</div></div></div>
</div>
<br>_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="noreferrer" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br>
<br></blockquote></div><br></div>