How to regenerate security certificates? CUCM 6.1.3

Hi,
Company has a call manager with 3 nodes on version 6.1.3:
- NODO1: 10.102.224.254
- NODO2: 10.102.224.253
- NODO3: 10.102.239.20
From S.O. web can be seen that some certs are going to expire. We have received a warning via e-mail. And we have checked opening certifications that expiration date is about to happen.
This is the security mode configuration:
Service parameters --> Publisher --> Call Manager-->Security Parameters
Cluster Security Mode: 1
CAPF Phone port:3804
CAPF Operation expires in (days):10
Enable caching: false
Certificates that are going to expire are the following:
CallManager_pem
CallManager_der
CAPF_pem
CAPF_der
CAPF-e09c40eb_pem
CAPF-e09c40eb_der
ipsec_cert_der
ipsec_cert_pem
NODO1_der
NODO1_pem
tomcat_cert_der
tomcat_cert_pem
At publisher, it can be seen no CTI file,
show itl
Executed command unsuccessfully
No valid command entered
There is only a CTL file, and it´s the following:
=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2014.02.19 17:47:46 =~=~=~=~=~=~=~=~=~=~=~=
show ctl   //Note: at the following file, some digits of the "SIGNATURE" have been changed with "*". And some name. Nothing else.
Length of CTL file: 5946
Parse CTL File
Version:          1.2
HeaderLength:          304 (BYTES)
BYTEPOS          TAG                    LENGTH          VALUE
3          SIGNERID          2          117
4          SIGNERNAME          56
5          SERIALNUMBER          10
6          CANAME          42
7          SIGNATUREINFO          2          15
8          DIGESTALGORTITHM          1
9          SIGNATUREALGOINFO          2          8
10          SIGNATUREALGORTITHM          1
11          SIGNATUREMODULUS          1
12          SIGNATURE          128
8d  e3  61  8a  d9  8  e  a3
8d  5b  82  6f  51  81  a3  1b
e2  fe  e5  57  66  f7  ab  54
f  69  fb ** 72  bf  3f  a1
ee  ea  a3  fb  b5  80  0  af
74  20  ac  b  92  b0  c5  fd
fa  f6  6e  52  c3  90  25  e1
2a  ** 83  f0  ee  4f  d3  9b
2e  6b  c4  4d  45  79  40  41
f2  b7  3  7e  7f  7a  **  b4
76  cc  45  e2  52  b1  4e  63
74  b1  a7  d8  36  97  22  47
8a  80  63  88  67  7e  7a  8d
2d ** eb  24  57  7b  c2  74
cf  4  bb  9d  dd  b1  a  a
e7  a9  5a  58  88  0  3f  67
14          FILENAME          12
15          TIMESTAMP          4
CTL Record #:1
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          1186
2          DNSNAME                    1
3          SUBJECTNAME          56          cn="SAST-ADN597e8314        ";ou=IPCBU;o="Cisco Systems
4          FUNCTION          2          System Administrator Security Token
5          ISSUERNAME          42          cn=Cisco Manufacturing CA;o=Cisco Systems
6          ISSUERNAME          10
7          PUBLICKEY          140
9          CERTIFICATE          902
10          IPADDRESS          4
This etoken was not used to sign the CTL file.
CTL Record #:2
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          1180
2          DNSNAME                    1
3          SUBJECTNAME          56          cn="SAST-ADN592dfe14        ";ou=IPCBU;o="Cisco Systems
4          FUNCTION          2          System Administrator Security Token
5          ISSUERNAME          42          cn=Cisco Manufacturing CA;o=Cisco Systems
6          ISSUERNAME          10
7          PUBLICKEY          141
9          CERTIFICATE          895
10          IPADDRESS          4
This etoken was used to sign the CTL file.
CTL Record #:3
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          765
2          DNSNAME                    15          10.102.224.253
3          SUBJECTNAME          13          cn=NODO2
4          FUNCTION          2          CCM+TFTP
5          ISSUERNAME          13          cn=NODO2
6          ISSUERNAME          8
7          PUBLICKEY          140
9          CERTIFICATE          541
10          IPADDRESS          4
CTL Record #:4
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          765
2          DNSNAME                    15          10.102.224.254
3          SUBJECTNAME          13          cn=NODO1
4          FUNCTION          2          CCM+TFTP
5          ISSUERNAME          13          cn=NODO1
6          ISSUERNAME          8
7          PUBLICKEY          140
9          CERTIFICATE          541
10          IPADDRESS          4
CTL Record #:5
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          982
2          DNSNAME                    15          10.102.224.254
3          SUBJECTNAME          43          cn=CAPF-e09c40eb;ou=AREA TIC;o=NOMBREX
4          FUNCTION          2          CAPF
5          ISSUERNAME          43          cn=CAPF-e09c40eb;ou=AREA TIC;o=NOMBREX
6          ISSUERNAME          8
7          PUBLICKEY          140
9          CERTIFICATE          698
10          IPADDRESS          4
CTL Record #:6
BYTEPOS          TAG                    LENGTH          VALUE
1          RECORDLENGTH          2          764
2          DNSNAME                    14          10.102.239.20
3          SUBJECTNAME          13          cn=NODO3
4          FUNCTION          2          CCM+TFTP
5          ISSUERNAME          13          cn=NODO3
6          ISSUERNAME          8
7          PUBLICKEY          140
9          CERTIFICATE          541
10          IPADDRESS          4
The CTL file was verified successfully.
Certificates at publisher are the following:
admin:show cert list own
tomcat
ipsec
CallManager
CAPF
admin:show cert list
ipsec-trust/NODO1.pem
ipsec-trust/NODO1.der
ipsec-trust/c92d8a04.0
CallManager-trust/CAP-RTP-001.pem
CallManager-trust/CAP-RTP-002.pem
CallManager-trust/Cisco_Manufacturing_CA.pem
CallManager-trust/Cisco_Root_CA_2048.pem
CallManager-trust/a0440f4c.0
CallManager-trust/a69d2e04.0
CallManager-trust/f7a74b2c.0
CallManager-trust/dcc12642.0
CallManager-trust/0d40b14e.0
CallManager-trust/CAPF-7EC94D72.pem
CallManager-trust/CAPF-97FA3FDE.pem
CallManager-trust/CAPF-e09c40eb.pem
CallManager-trust/3e92ebd9.0
CallManager-trust/8eb380b0.0
CAPF-trust/CAP-RTP-001.pem
CAPF-trust/CAP-RTP-002.pem
CAPF-trust/Cisco_Manufacturing_CA.pem
CAPF-trust/Cisco_Root_CA_2048.pem
CAPF-trust/a0440f4c.0
CAPF-trust/a69d2e04.0
[1mPress <enter> for 1 line, <space> for one page, or <q> to quit [0m
[KCAPF-trust/f7a74b2c.0
CAPF-trust/CAPF.der
CAPF-trust/CAPF.pem
CAPF-trust/dcc12642.0
CAPF-trust/8eb380b0.0
admin:utils service list
Requesting service status, please wait...
System SSH [STARTED]
Cluster Manager [STARTED]
Service Manager is running
Getting list of all services
>> Return code = 0
A Cisco DB[STARTED]
A Cisco DB Replicator[STARTED]
Cisco AMC Service[STARTED]
Cisco AXL Web Service[STARTED]
Cisco Bulk Provisioning Service[STARTED]
Cisco CAR Scheduler[STARTED]
Cisco CAR Web Service[STARTED]
Cisco CDP[STARTED]
Cisco CDP Agent[STARTED]
Cisco CDR Agent[STARTED]
Cisco CDR Repository Manager[STARTED]
Cisco CTIManager[STARTED]
Cisco CTL Provider[STARTED]
Cisco CallManager[STARTED]
Cisco CallManager Admin[STARTED]
Cisco CallManager Attendant Console Server[STARTED]
Cisco CallManager Cisco IP Phone Services[STARTED]
Cisco CallManager Personal Directory[STARTED]
Cisco CallManager SNMP Service[STARTED]
Cisco CallManager Serviceability[STARTED]
Cisco CallManager Serviceability RTMT[STARTED]
Cisco Certificate Authority Proxy Function[STARTED]
Cisco Certificate Expiry Monitor[STARTED]
Cisco DRF Local[STARTED]
Cisco DRF Master[STARTED]
Cisco Database Layer Monitor[STARTED]
Cisco Dialed Number Analyzer[STARTED]
Cisco DirSync[STARTED]
Cisco Extended Functions[STARTED]
Cisco Extension Mobility Application[STARTED]
Cisco IP Manager Assistant[STARTED]
Cisco IP Voice Media Streaming App[STARTED]
Cisco License Manager[STARTED]
Cisco Log Partition Monitoring Tool[STARTED]
Cisco RIS Data Collector[STARTED]
Cisco RTMT Reporter Servlet[STARTED]
Cisco SOAP - CDRonDemand Service[STARTED]
Cisco Serviceability Reporter[STARTED]
Cisco Syslog Agent[STARTED]
Cisco Tftp[STARTED]
Cisco Tomcat[STARTED]
Cisco Tomcat Stats Servlet[STARTED]
Cisco Trace Collection Service[STARTED]
Cisco Trace Collection Servlet[STARTED]
Cisco UXL Web Service[STARTED]
Cisco WebDialer Web Service[STARTED]
Host Resources Agent[STARTED]
MIB2 Agent[STARTED]
Native Agent Adapter[STARTED]
SNMP Master Agent[STARTED]
SOAP -Log Collection APIs[STARTED]
SOAP -Performance Monitoring APIs[STARTED]
SOAP -Real-Time Service APIs[STARTED]
System Application Agent[STARTED]
Cisco DHCP Monitor Service[STOPPED]  Service Not Activated
Cisco Extension Mobility[STOPPED]  Service Not Activated
Cisco Messaging Interface[STOPPED]  Service Not Activated
Cisco TAPS Service[STOPPED]  Service Not Activated
Cisco Unified Mobile Voice Access Service[STOPPED]  Service Not Activated
Primary Node =true
admin:
Perfil de seguridad Ej:para un CP-7960
-Phone Security Profile Info
Device Protocol: SCCP
Name: SP_7960_Encriptado
Description: Migrated Profile: Sec_mode 3 Auth_mode 2
Device Security Mode: Encrypted
-Phone Security profile CAPF Info
Authentication mode: By null string
Key Size: 1024
At this forum, it says for version 5x to /7x I have simply to regenerate certificates:
http://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-version-50/99815-ccm-sec-cert.html
These are the doubts I have:
- Is it necessary to regenerate any certificate in first plase?, if so ¿what is the place I should follow for each certificate?
- Is it necessary to restart any service before regenerating the certificates? for version 8.0 and higher, I saw that it´s necessary to restart TFTP and Call Manager services.
- After regenerating certificates, is it necessary to create a new CTL file? If so, Do I need the two tokens we used to create CTL file at the begining?
- Regarding CAPF certificate. Do i need to push the LSC certificates to the phones? Or I just need to reset phones to do so?
Thank you in advance!

Found the answer - Need to "Enable Advance Ad-Hoc Conference" under service parameters.

Similar Messages

  • How to use security certificate with Business service

    Hi,
    Information:
    I need to use a security certificate for connection from Business service to legacy system.
    I have created PKI mapper in WebLogic console, deployed keystore on server and Service Key Provider in OSB.
    I can see can connect the certificate in OSB console through the Service Key Provider.
    I have done Authentication setting in the Business service "HTTP Transport Configuration" as "Client Certificate".
    Problem:
    Now whenever I try to invoke BS, the username, password and security key provider is asked at the prompt. Should not the BS collect security certificate automatically? Again,
    when i put username and password as that of WebLogic sbconsole; the error pops up with following message :
    <env:Envelope xmlns:env="http://schemas.xmlsoap.org/soap/envelope/">
         <env:Header />
         <env:Body>
              <env:Fault>
                   <faultcode>env:Server</faultcode>
                   <faultstring>Failed to process signature.null</faultstring>
              </env:Fault>
         </env:Body>
    </env:Envelope>
    If I don't supply username password and certificate at the time of invoking the message pops up as : "The service requires a digital signature, you must specify a service key provider which has a digital signature credential."
    I think some mistake is done in the above steps, could anybody please clarify?

    The problem was resolved with upgrade to version 10.1.3.4.

  • How to read security certificates from registry using java 1.4

    Hi All,
    I installed one Security certificate in IE browser. that certificate is UNExportable which contains private keys which are imported to use while server cuommunication.
    Now have to send that certificate for authentication to vendor server using java(J2SDK 1.4).I tried allways to do cummunication but filed due to unabalability of private key.
    Here I want to read that certificate from windows sertificate registry store which is installed from IE.
    Is there any way to read IE installed certificates using java. If so please provide me that code.
    Its very URGENT for me.....please help
    thank you
    Vinod

    while exporting the certificate the am able to export only public keys, private key option is disabled. but those private keys are very important for my communication. I should pass those private keys to vendor for authentication purpose.
    That's way am paling to read certificate from windows registry. but am new to these concepts.
    can anybody have code to read certificates from windows registry using java 1.4?

  • When I try to download the latest version of iTunes on my iPod Classic I get the message that "iTunes has an invalid signature" and that "Content was blocked because it was not signed by a valid security certificate.  Anyone know how to fix this?

    When I try to download the latest version of iTunes from apple.com, I get the message "Content was blocked because it was not signed by a valid security certificate."When I open iTunes and try to download the latest version there, I get the message "iTunes has an invalid signature.  The download has been removed."  I have also gotten an Internet Script Error stating that an error has occured in Line 0, Char O and that "Access is denied to images.apple.com/global/scripts/lib/iepngfix.htc."  This problem has never occurred with earlier versions of ITunes.  Anyone know how to fix this problem? 

    Are you downloading iTunes form an Apple website or somewhere else? If the answer is somewhere else, try downloading it from Apple. Click on iTunes in the black menu bar above and go from there.
    Let us know what happens.

  • After upgrading to Firefox 10.0.2 there is no way to proceed to a website with an invalid security certificate. How do you proceed to these websites in the new release? The fault page only has a button that says "Try again."

    Using Firefox 10.0.2 for Mac.
    In trying to proceed to various websites (corporate such as dlnet.delta.com (expired certificate), government such as https://www.homeport.navy.mil/links/owa-navy-links/ ) with "invalid" security certificates, Firefox 10.0.2 does not have a button on the error page to continue on to the website. How can you do this using Firefox 10.0.2? I have not found any settings in Firefox preferences to enable this capability either.
    Thx.

    Start Firefox in <u>[[Safe Mode]]</u> to check if one of the extensions or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox/Tools > Add-ons > Appearance/Themes).
    *Don't make any changes on the Safe mode start window.
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes

  • How do i deal with 'security certificate' issues on my iPad2? I'm unable to answer the security questions that pop up when Im trying to download an app because the pop up does not load properly...

    Basically my Ipad2 stopped allowing me to go to sites such as Tumblr a little while ago. It wouldn't display the page properly because of 'security certificate' issues. This in itself would not have been such a problem, but when I went to the App store to try and download the Tumblr App, a pop up appeared asking me to answer some security questions before I could successfully install the App. However, the pop up would not display correctly because of 'security certificate' issues and as a result I can't download any apps from the App Store. Can anyone help with this??

    Well, I maged to delete some stuff, download the update...
    My Mac mail is still not ok. Still only displays today, yesterday and everything is the 16th of the month previous to this?
    All a bit strange to say the least any suggestons on how to resolve this.
    I now have a second issue in all my emails at the very top of each it describes in detail the full information of
              Delivered-To:  
              Received:  
              Received:  
              Received:  
              Received:  
              X-Received:  
              Return-Path:  
              Received-Spf:
              Authentication-Results:
              Content-Type:  
              Mime-Version:  
              X-Mailer:  
              X-Cloudmark-Analysis:  
    Surely this should not be displayed rather insecure I would think. Any suggestions on how to amend

  • How do I accept a previously rejected security certificate?

    I am trying to use a site that has a security certificate. I accidentally refused it. I now get the error message " cannot connect to Citrix XenApp server SSL Error 61: You have not chosen to trust 'COMODO High Assurance Server CA'
    How do I set Firefox to accept this certificate? (I want to unrefuse.)
    Thanks for the help. Joe Berkow [email protected]

    That is not a problem with Firefox.<br />
    You need to install that certificate in the Citrix local database.
    * http://support.citrix.com/article/CTX711855

  • How to delete an expired security certificate?

    Each time I open a fresh Firefox page, I get a message popping up 4 times informing me that a security certificate for a cashback set-up that no longer exists, has expired. How do I get rid of it?

    Thank you for taking the time to reply. Alas, I have tried restarting Firefox but can find no "Safe Mode" in the menu at the top of the screen. My Firefox is old, having come out of Noah's Ark all of 4 years ago, an eternity for the weirdos that design these things. (Version 13 something). So the problem is still there. Not that it means much, as all I have to do is click on each of the four or five irritating messages that pop up each time I start the bloody thing. And anyway, as Firefox has decided to stop "supporting" my version, I'll soon have to find a navigator that I can still use. Or buy a new Macintosh, which I'm certainly not prepared to do; planned obsolescence has its limits.

  • How to extract information from client security certificates and display it

    Hi guys,
    just wanted to know is it possible to extract information from an digital security certificate and get that displayed on top level navigation of the portal. So for ex. I want to extract the clients name and code and area from where they come from to be displayed on top level.
    thanks
    anton

    RoopeshV wrote:
    Hi,
    The below code shows how to read from txt file and display in the perticular fields.
    Why have you used waveform?
    Regards,
    Roopesh
    There are so many things wrong with this VI, I'm not even sure where to start.
    Hard-coding paths that point to your user folder on the block diagram. What if somebody else tries to run it? They'll get an error. What if somebody tries to run this on Windows 7? They'll get an error. What if somebody tries to run this on a Mac or Linux? They'll get an error.
    Not using Read From Spreadsheet File.
    Use of local variables to populate an array.
    Cannot insert values into an empty array.
    What if there's a line missing from the text file? Now your data will not line up. Your case structure does handle this.
    Also, how does this answer the poster's question?

  • 10.10.1.2:8090 uses an invalid security certificate. The certificate is not trusted because no issuer chain was provided. The certificate is only valid for a id="cert_domain_link" please help me how to fix such type of problems?

    sir, each time when i open my browser i'm facing such type of error certificate and closing browser at the same instant. i don't know how to fix it please help me

    Hi,
    If you click on the certificate '''Details''' it would show the root Certificate Authority (the topmost one) and any intermediate CAs that signed/issued this security certificate. You would need at least the root CA certificate to be installed ('''Import''') and trusted in the Firefox certificate database ('''Tools '''('''Alt '''+ '''T''') > '''Options '''> '''Advanced '''> '''Encryption '''> '''View Certificates''' > '''Authorities'''), though sometimes depending on the server configuration you may need all the certificates in the hierarchy to be installed.
    [https://support.mozilla.org/en-US/kb/Options%20window%20-%20Advanced%20panel?as=u Options > Advanced]
    [https://support.mozilla.org/en-US/kb/Options%20window Options]

  • How do I restore default SSL security certificates/authorities/servers?

    A website I visit often was having SSL certificate issues. I did not know what certificate I needed to remove in order to get it working again... So I removed ALL of my security certificates/authorities.
    I did not realize it would be near impossible to restore them.
    Now every website I go to is "untrusted" and I need to confirm a security exception.
    How do I restore the certificates/authorities to the default state?
    I tried removing firefox and reinstalling, but that did not fix it.
    Any help would be greatly appreciated. At this point I'm tempted to just switch to Chrome or another browser.

    See '''cor-el''' reply - Solution Chosen
    https://support.mozilla.org/en-US/questions/878694
    thank you

  • HT2801 I can't access a website because my mobile me security certificate has expired.  It says it expires on June 30, 2012, but I should have another 5 days before moving to iCloud. How can I extend this security certificate till then?

    I'm unable to access a website because it says my "mobile me security certificate has expired." When checking the account, it says it expires on June 30, 2012. I realize that's the date to switch to iCloud, but how can I reinstate or update the certificate now? I should have 5 days left to use it.  Any help would be appreciated - thanks!

    PORT YOUR NUMBER OUT...T MOBILE WILL PAY YOUR ETF IF YOU GIVE THEM YOUR VERIZON PHONES.

  • How to Regenerate Root CA certificate after revoking it using ocactl OAS10g

    Good Evening,
    I'm fairly new to the world of OAS Administration. I had a problem with the OracleAS Certificate Authority administration page, cause the administrator certificate had expired. When I was looking for ways to regenerate it I tried to revoke it by hand, but mistakenly revoked the CA certificate with the following command:
    $ORACLE_HOME/oca/bin/ocactl revokecert -type CA -reason UNSPECIFIED
    In the documentation there is no information on how to make OracleAS Certificate Authority functional again. Do I have to reinstall? Where can I get a new Root cerficate to replace the one I revoked and make the installation usable again.
    It is a UAT environment, with only one user currently.
    OracleAS Certificate Authority 10g (10.1.2.1.0)
    Thanks for your help, and excuse my ignorance on the subject
    I. Neva
    Oracle DBA

    Found the solution:
    $ORACLE_HOME/oca/bin/ocactl generatewallet -type CA
         *** Important: CN (Common Name) should be different from hostname
    $ORACLE_HOME/oca/bin/ocactl generatewallet -type CASSL
         *** Important: CN (Common Name) should be the fully quailified hostname

  • Igot error invalid security certificate every time i load page how can i ix it?

    Igot error invalid security certificate every time i load page how can i ix it?
    http://image.ohozaa.com/view/6qb2o

    Yes your calendar date is wrong as you have it set as January 28, 2554 as per your image.
    http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/windows_date_change_date.mspx?mfr=true

  • How to edit IE8 security certificate?

    Can anyone tell me how to add additional secondary DNS servers to an internet explorer 8 security certificate? I have a friend who is still running Windows XP and IE8, and wants to access gmail.  Google has revoked security certificates for IE8 and
    left a message that IE8 is basically so old that it is no longer compatible. However, it seems to work fine, just with security certificate violation warnings coming up all the time.
    So, I followed instructions to put my own security certificate in place, and have run into a problem that the certificate is for mail.google.com, but what shows up in the naviagation bar is gmail.com - there is a redirect going on at google.
    There appears to be a place on the security certificate to put in secondary DNS's, and it already has some such as inbox.google.com, and so on.  But I cannot see how to add in "gmail.com"  There's an "edit" button on the certificate
    details, but it is greyed out.   Can anyone tell me how to do edits on the security certificate?
    Thank you.
    rdatlanta

    Hi,
    try taking google out of the IE Trusted sites list and uninstalling/updating the google toolbar.
    Questions regarding Internet Explorer 8, 9 and 10 and Internet Explorer 11 for the IT Pro Audience. Topics covered are: Installation, Deployment, Configuration, Security, Group Policy, Management questions. If you are a consumer looking for answers or to
    raise a question, it's highly recommended you head on over to http://answers.microsoft.com/en-us
    Rob^_^

Maybe you are looking for