<div dir="ltr">We've been flipping a lot of customers over to NameCheap now.  $50/year for multi-SAN DV certificates is pretty hard to beat.  For CUCM/Unity/IM&P/UCCX/Expressway, ends up more like $250-$300/year.<br><br>They seem to issue certs pretty immediately since it's just Domain Verification using email.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Feb 18, 2022 at 1:17 PM Nick Russo via cisco-voip <<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><div style="font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px"><div></div>
        <div dir="ltr">Unfortunately, Cisco doesn't allow for * certs with the UC platform.  If this is for Jabber MRA, they recently added support for ACME certificates, but I haven't used that.  The cheapest CA signed certs I've been able to find is <a href="http://ssls.com" target="_blank">ssls.com</a> and the full set of certs for a typical cluster is going to set you back about $900 a year.  They have a couple of Collaboration packages that you can use for the multiple domains.  Also, they work well enough, but the support for <a href="http://ssls.com" target="_blank">ssls.com</a> is pretty weak, so plan on at least a week to get your certs ordered, approved, and installed.</div><div><br></div>
        
        </div><div id="gmail-m_-453707674388908684ydp33b5cb59yahoo_quoted_5218489103">
            <div style="font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:13px;color:rgb(38,40,42)">
                
                <div>
                    On Friday, February 18, 2022, 09:39:50 AM PST, Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca" target="_blank">lelio@uoguelph.ca</a>> wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div><div dir="ltr">We use Entrust. But I think we had some sort of "Contract" that allowed for a specific number of certs to be issued, all on the credit system. Regardless of SANs. <br clear="none"><br clear="none">But, you're right. Cisco collab is an expensive solution to provide certs for.<br clear="none"><br clear="none">I'm really hoping that <a shape="rect" href="https://www.incommon.org/certificates/subscribe/" rel="nofollow" target="_blank">https://www.incommon.org/certificates/subscribe/ </a>opens up to EDUs outside of the U.S. some time (soon).<br clear="none"><br clear="none">-----Original Message-----<br clear="none">From: cisco-voip <<a shape="rect" href="mailto:cisco-voip-bounces@puck.nether.net" rel="nofollow" target="_blank">cisco-voip-bounces@puck.nether.net</a>> On Behalf Of James Andrewartha<br clear="none">Sent: Friday, February 18, 2022 4:28 AM<br clear="none">To: <a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a><br clear="none">Subject: Re: [cisco-voip] [EXTERNAL] Re: Cost-Effective Public Certificate Authority for CUCM certificates<br clear="none"><br clear="none">CAUTION: This email originated from outside of the University of Guelph. Do not click links or open attachments unless you recognize the sender and know the content is safe. If in doubt, forward suspicious emails to <a shape="rect" href="mailto:IThelp@uoguelph.ca" rel="nofollow" target="_blank">IThelp@uoguelph.ca</a><br clear="none"><br clear="none"><br clear="none">Digicert have killed the fact you could issue a cert for <a href="http://host.sub.example.com" target="_blank">host.sub.example.com</a> on your *.<a href="http://example.com" target="_blank">example.com</a> wildcard, instead they want to charge you extra for those hosts so now I'm shopping around. The good news is there's now other places that will do wildcards with unlimited reissues (which most call "unlimited server licenses").<br clear="none"><br clear="none">I tried Comodo/Sectigo Positive Multi Domain Wildcard SSL which can even have multiple wildcards on the one certificate, but it only accepts CSRs for *.<a href="http://example.com" target="_blank">example.com</a>, which UCM/UC/IM&P won't generate. But perhaps that's a limitation of the reseller I used. They also have the Comodo/Sectigo Multi Domain SSL Certificate (FLEX) which lets you have host SANs, but will charge you for each one.<br clear="none"><br clear="none">Anyone had success with any other CAs recently?<br clear="none"><br clear="none">--<br clear="none">James Andrewartha<br clear="none">Network & Projects Engineer<br clear="none">Christ Church Grammar School<br clear="none">Claremont, Western Australia<br clear="none">Ph. (08) 9442 1757<br clear="none">Mob. 0424 160 877<br clear="none"><br clear="none">On 31/3/20 04:49, Brian Meade wrote:<br clear="none">> In this case, we're doing public certificates internally as well for <br clear="none">> CUCM Tomcat, Unity Connection Tomcat, UCCX Tomcat, and IM&P CUP-XMPP.<br clear="none">> <br clear="none">> Adding the multiple presence domains is pretty easy on the IM&P side <br clear="none">> and it will automatically add SAN's for those domains in the CSR.<br clear="none">> <br clear="none">> Expressway-E will also automatically add all domains to the CSR.<br clear="none">> <br clear="none">> On Mon, Mar 30, 2020 at 4:07 PM Jonatan Quezada <br clear="none">> <<a shape="rect" href="mailto:jonatan.quezada@chemeketa.edu" rel="nofollow" target="_blank">jonatan.quezada@chemeketa.edu</a> <mailto:<a shape="rect" href="mailto:jonatan.quezada@chemeketa.edu" rel="nofollow" target="_blank">jonatan.quezada@chemeketa.edu</a>>><br clear="none">> wrote:<br clear="none">> <br clear="none">>     Brian, How challenging was it to do the jabber on all three domains?<br clear="none">> <br clear="none">>     Where do you need the multiDomain cert, on the VCS-edge connector<br clear="none">>     right? Im looking to see what it would take to get this going for<br clear="none">>     our remote workers even though it seems<br clear="none">>     like there are few things to make sure are in place first.<br clear="none">> <br clear="none">>     for so far its the :<br clear="none">> <br clear="none">>     certs for dual domain- how<br clear="none">>     provision jabber users<br clear="none">> <br clear="none">> <br clear="none">>     On Mon, Mar 30, 2020 at 12:28 PM Brian Meade <<a shape="rect" href="mailto:bmeade90@vt.edu" rel="nofollow" target="_blank">bmeade90@vt.edu</a><br clear="none">>     <mailto:<a shape="rect" href="mailto:bmeade90@vt.edu" rel="nofollow" target="_blank">bmeade90@vt.edu</a>>> wrote:<br clear="none">> <br clear="none">>         I was originally going to go with that wildcard option but this<br clear="none">>         customer has 3 different presence domains to match their email<br clear="none">>         domains which makes the CUP-XMPP cert more complicated.<br clear="none">> <br clear="none">>         This is my personal email so no access to InCommon certificates<br clear="none">>         unfortunately.<br clear="none">> <br clear="none">>         On Mon, Mar 30, 2020 at 2:59 PM Matthew Ballard<br clear="none">>         <<a shape="rect" href="mailto:mballard@otis.edu" rel="nofollow" target="_blank">mballard@otis.edu</a> <mailto:<a shape="rect" href="mailto:mballard@otis.edu" rel="nofollow" target="_blank">mballard@otis.edu</a>>> wrote:<br clear="none">> <br clear="none">>             We used to use DigiCert Wildcard which offers that (where<br clear="none">>             you can issue multiple certificates with different private<br clear="none">>             keys from the same wildcard cert/purchase).____<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             We switched to using InCommon certificates, which it looks<br clear="none">>             like your University also subscribes to.  You should be able<br clear="none">>             to get them internally from whomever licensed that there, as<br clear="none">>             it’s a flat fee service for unlimited certificates.____<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             Matthew Ballard____<br clear="none">> <br clear="none">>             Director of Technology Infrastructure____<br clear="none">> <br clear="none">>             Information Systems____<br clear="none">> <br clear="none">>             Otis College of Art and Design____<br clear="none">> <br clear="none">>             <a shape="rect" href="mailto:mballard@otis.edu" rel="nofollow" target="_blank">mballard@otis.edu</a> <mailto:<a shape="rect" href="mailto:mballard@otis.edu" rel="nofollow" target="_blank">mballard@otis.edu</a>>____<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             *From:*cisco-voip <<a shape="rect" href="mailto:cisco-voip-bounces@puck.nether.net" rel="nofollow" target="_blank">cisco-voip-bounces@puck.nether.net</a><br clear="none">>             <mailto:<a shape="rect" href="mailto:cisco-voip-bounces@puck.nether.net" rel="nofollow" target="_blank">cisco-voip-bounces@puck.nether.net</a>>> *On Behalf Of<br clear="none">>             *Brian Meade<br clear="none">>             *Sent:* Monday, March 30, 2020 11:42 AM<br clear="none">>             *To:* cisco-voip voyp list <<a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a><br clear="none">>             <mailto:<a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a>>><br clear="none">>             *Subject:* [cisco-voip] Cost-Effective Public Certificate<br clear="none">>             Authority for CUCM certificates____<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             Does anyone know of any public certificate authorities that<br clear="none">>             have cheaper multi-server SAN certificate options?  I had<br clear="none">>             seen some in the past that let you buy a wildcard and then<br clear="none">>             can submit CSR's against that still but having trouble<br clear="none">>             finding that now.____<br clear="none">> <br clear="none">>             __ __<br clear="none">> <br clear="none">>             Trying to avoid buying 4 multi-server certificates to cover<br clear="none">>             CUCM Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P <br clear="none">> XMPP.____<br clear="none">> <br clear="none">>         _______________________________________________<br clear="none">>         cisco-voip mailing list<br clear="none">>         <a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a> <mailto:<a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a>><br clear="none">>         <a shape="rect" href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="nofollow" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br clear="none">>         <<a shape="rect" href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="nofollow" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a>><br clear="none">> <br clear="none">> <br clear="none">> <br clear="none">>     -- <br clear="none">>     During this time of remote work, There will be the need for<br clear="none">>     connectivity to other devices such as a cell phone. If you require<br clear="none">>     assistance forwarding your desk phone to a remote cell or message<br clear="none">>     phone, please email with desk number and where we are forwarding<br clear="none">>     calls. I can do these remotely.<br clear="none">> <br clear="none">>     Johnny Q<br clear="none">>     Voice Technology Analyst II<br clear="none">>     Chemeketa Community College<br clear="none">>     <a shape="rect" href="mailto:Johnny.Q@chemeketa.edu" rel="nofollow" target="_blank">Johnny.Q@chemeketa.edu</a> <mailto:<a shape="rect" href="mailto:Johnny.Q@chemeketa.edu" rel="nofollow" target="_blank">Johnny.Q@chemeketa.edu</a>><br clear="none">>     Building 22 Room 130<br clear="none">>     Work 5033995294<br clear="none">>     Cell 5035769873<br clear="none">>     FAX 5033995549<div id="gmail-m_-453707674388908684ydp33b5cb59yqtfd56088"><br clear="none">> <br clear="none">> <br clear="none">> _______________________________________________<br clear="none">> cisco-voip mailing list<br clear="none">> <a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a><br clear="none">> <a shape="rect" href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="nofollow" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br clear="none"><br clear="none">_______________________________________________<br clear="none">cisco-voip mailing list<br clear="none"><a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a><br clear="none"><a shape="rect" href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="nofollow" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br clear="none">_______________________________________________<br clear="none">cisco-voip mailing list<br clear="none"><a shape="rect" href="mailto:cisco-voip@puck.nether.net" rel="nofollow" target="_blank">cisco-voip@puck.nether.net</a><br clear="none"><a shape="rect" href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="nofollow" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br clear="none"></div></div></div>
            </div>
        </div></div>_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net" target="_blank">cisco-voip@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/cisco-voip" rel="noreferrer" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br>
</blockquote></div>