Prime Collaboration 360 internal CA certificate

Hello all,
I have installed Prime Collaboration Assurance (10.6) plus Prime Collaboration Provisioning (10.6)  and I have attached both with the Prime Collaboration 360 option.
I have tried to install SSL certificates signed by the internal CA. With Prime Collaboration Assurance I have had success, doing it from cli, but I can not  to do the same procedure with Prime Provisioning because is not possible to access cli with root privileges.
My question is: How Cisco have planned to install certificates on Prime Provisioning?... or one must to decide between install certificates on Prime Assurance or configuring Prime 360...
Thanks

Emilo,
For PCP revs below 10.6 certs are loaded from the CLI with root access. Starting in PCP 10.6 cert installation is done from the product Administration/Updates UI.
Starting in PCP 10.6 and continuing for the next couple of revs, you will see all the CLI related functions move into the product Administration screens.
Regards

Similar Messages

  • Access to Prime Collaboration Deployment 10.5 software/OVA?

    Cisco Forum:
    How might a person obtain a copy of Cisco's Prime Collaboration Deployment software/OVA?
    Downloading Cisco software lists lots of Prime Collaboration 10.5 offerings but not the Deployment option.  Cisco's PUT Tool offers Prime Collaboration Standard 10.X but is failing with an internal error before I can even determine what might be contained with it. 
    How might Cisco's PCD software/OVA be obtained?
    Thank you.
    Dan

    for OVA
    Cisco only supports virtualized deployments of Cisco Prime Collaboration Deployment. PCD is deployed using an OVA that contains the pre-installed PCD application. This OVA is obtained with a licensed copy of Cisco Unified Communications Manager Release 10.5(1) software. For information about how to extract and deploy the PCD_VAPP.OVA file,
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/rel_notes/PCD/CUCM_BK_PB8976C2_00_pcd_rns_1001/CUCM_BK_PB8976C2_00_pcd_rns_1001_chapter_01.html
    for extracting OVA
    Step 1  
    Extract the PCD_VAPP.OVA from the pcd_vApp_UCOS_10.xxxxx.iso file. A new PCD_VAPP.OVA file is created. Verify the file size; ISO and OVA files do not have the same file size.
    Step 2  
    Deploy the PCD_VAPP.OVA file in vCenter to install Cisco Prime Collaboration Deployment. If you are using vSphere client, the name of this file may be PCD_VAPP.OVA. If you are using the VMware vSphere web client to deploy the file, you must first change the name to PCD_VAPP.ova (lowercase) before deploying the file.
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/pcdadmin/10_5_1/CUCM_BK_U35347D2_00_pcd-administration-guide-1051/CUCM_BK_U35347D2_00_ucmap-administration-guide-1051_chapter_01.html#CUCM_TK_E008CD66_00

  • VCS registered endpoints not displayed in Cisco Prime Collaboration 10.5 Assurance and Analytics

    Hi,
    We have been able to successfully add VCS in Prime Collaboration Assurance and Analytics 10.5 however the endpoints registered with VCS are not displayed in the list of devices. Though, we have been able to add a video codec manually which originally is registered with VCS.
    Thanks in advance
    Kunal

    Hi F,
    After investigation this issue, we came to know that this is due to the use of 4096 bit ssl certificate by the VCS.
    This is currently not supported by Prime Collaboration 10.5.1 and will be fixed in release 10.6 (available beginning of December).
    In the mean time you will be able to discover the VCS is you change the default VCS certificate to match the types that are supported by Prime Collaboration.
    Regards,
    Kunal

  • Cisco Prime Collaboration Assurance _ Web login

    I have recently deployed Cisco Prime Collaboration Assurance standard within our Vmware environment with the view to evaluate and deploy into production.
    I have successfully deployed within the environment and can log into the appliance via SSH via the root, admin and globaladmin account however when I try to login through the Web Gui with the above accounts, i am getting the " invalid username or password" error.
    Can anyone provide guidance please 
    Peter

    Hi Peter,
    Never faced such issue.
    Look into the bugs if helps.
    PC 9.0 After restore from backup, cannot login - invalid password
    CSCui00260
    Description
    Symptom:
    cannot log in to the GUI with any known username/pw including globaladmin account.
    tomcat logs will show 'untrusted certificate' errors.
    Conditions:
    seen after a fresh restore from backup on a new server.
    Workaround:
    contact BU for workaround.
    Assurance password for globaladmin with * at end or beginning fails
    CSCue81630
    Description
    Symptom:
    User 'globaladmin' is unable to login to Prime Collaboration Assurance
    Conditions:
    The password for 'globaladmin' contains '*' at the beginning or end of the password
    Workaround:
    Do not use '*' character at the beginning or end of the password
    regds,
    aman

  • Prime Collaboration will not sync with CUCM

    Hello All
    I do not normally find myself asking questions but I am new with the BE6K. I have installed prime collaboration. Added CUCM,CUC,CUPS as devices. I have added the name and the IP to a media server capability of Unified CM. I have then updated the call processor to the correct version. I only have the option for https. I have LDAP Sychronization set to Sync and Authenticate and I have set the password correctly for the user account.
    When I go to synchronize the infrastructure I get
    ERROR: Failed to sync ConferenceBridge
    ERROR: Failed to sync VoiceMailPort
    ERROR: Failed to sync VoiceMailPilot
    ERROR: Failed to sync IpPhoneServices
    ERROR: Failed to sync VoiceDeviceGroup
    ERROR: Sync aborted due to errors.
    I know that LDAP is working fine on CUCM. I am sure I can figure this out manually in all of the different servers but would like to get PCP working. I can't sell it to a customer if we can't get it working.
    I do wonder if it is a certificate issue because CUCM always prompts. I can fix this easy on my desktop by just installing the cert. Could that be the answer and if so how would I import the cert or the chain if I added a computer cert to CUCM from our certificate server?
    How would I go about troubleshooting this? Any help is greatly appreciated.

    Thanks for the fast response.  CUCM is 9.1(2) and I would believe that PCP is the same.  I did notice at the splash scree that it says my cucm is "host or service not found".

  • Does Cisco Media Services Interface mark RTP and Signaling packets regardless of Cisco Prime Collaboration/MediaNet Deployment?

    Hi there,
    I'm deploying Cisco UC Integration Lync 9.2(5). There's a QoS portion which states that you can install Cisco Media Services Interface on the user's PC and is to be used with Cisco Prime Collaboration or MediaNet:
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucilync/9/CUCI_BK_C0545A41_00_cisco-uc-integration-for-microsoft/CUCI_BK_C0545A41_00_cisco-uc-integration-for-microsoft_chapter_010.html#CUCI_CN_IDBE72E9_00
    If we don't have Cisco Prime Collaboration or MediaNet, does Cisco Media Services Interface mark RTP and Siganling packets on the outbound regardless? Or do I have to manually set the DSCP values for the PC?
    Thanks,
    John

    When you were placing the internal test calls, where was your phone located?   The RTP streams are usually only set up between the two endpoints (assuming no transcoder or MTP is used).
    Have you have already checked calls between IP phones at your central site (where Unity is located) and IP Phones at site A?   Are these working fine?   If not, then it's likely you do have a QoS issue over the WAN to Site A.
    Have you confirmed whether or not calls from the PSTN gateway at site A experience any voice QoS issues when transferred to an IP Phone at the central site?
    Is the same codec is being used for the MGCP gateway as for IP Phones at that site (check the Region settings for the Device Pool it's in)?
    If these things have all been checked, then you may want to consider collecting a simultaneous sniffer trace from each end of a single call, and comparing what's seen at the two endpoints.
    Kind regards,
    Craig

  • How many domains can Prime Collaboration Advanced manage with the BE6000?

    The BE6000 Administration guide states that "Most BE6K deployments have a single domain as part of a Standard Prime installation. Multiple domains are available with Prime Collaboration Advanced (available for purchase) that can be used for complex Business Edition 6000 deployments."
    How many domains can Prime Collaboration Advanced manage with the BE6000 solution? How do we order and deploy Prime Collaboration Advanced with the BE6000 solution?

    http://docwiki.cisco.com/wiki/System_Capacity_for_Cisco_Prime_Collaboration_10.0

  • Cisco Prime Collaboration Assurance IPPhone 3901 no serial number report

    Hi All,
    I have installed Cisco Prime Collaboration Assurance in my office and try to create phone inventory report , so far no problem , but when i add IPPhone 3901 there no serial number in the report , I have enable web access on the phone , i can see the serial number by click the IP  .
    any help ?
    Best Regards,
    Tommy

  • Cisco Prime Collaboration Deployment with BE7K and VMWare license

    Hello, I am looking for some help trying to figure out if Cisco Prime Collaboration Deployment can be used to upgrade our existing 7.1.5 cluster.  From what I have read there is a API problem with the VMWare license that comes with the BE7K.  But after reviewing the BOM/quote from my VAR it lists the foundation license which based of the release notes is supported.
    UCSS-U-VMW-FND-5-1
    UCSS Cisco UC Virt. Foundation  Five Year - 1 server
    Has anybody out there had expericne with PCD and BE7K'?
    This is from release notes of PCD
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/rel_notes/10_5_1/CUCM_BK_P139675A_00_pcd-rns-1051/CUCM_BK_P139675A_00_pcd-rns-1051_chapter_010.html
    Search for “Business Edition 7000” and it will state it is not supported with PCD.  It is because the licenses that the BE 6k and 7K are shipped with don’t enable certain VMware APIs that PCD needs.
    “Virtualization Software License Compatibility
    Cisco Prime Collaboration Deployment is not compatible with all license types of VMware vSphere ESXi, as some licenses do not enable required VMware APIs.
    The following are compatible with Cisco Prime Collaboration Deployment:
    Cisco UC Virtualization Foundation (appears as "Foundation Edition" in vSphere Client)
    VMware vSphere Standard Edition, Enterprise Edition, or Enterprise Plus Edition
    Evaluation mode license
    The following are not compatible with Cisco Prime Collaboration Deployment:
    Cisco UC Virtualization Hypervisor (appears as "Hypervisor Edition" in vSphere Client)-preloaded on Cisco Business Edition 6000 and Business Edition 7000
    VMware vSphere Hypervisor Edition
    Any help would be appreacted.
    JP

    Thanks Jamie for repsonding, we haven't made any purchase's yet but I wanted to ensure we are purchasing a solution that won't lead to a lot of frustration.  We only have 1000 phones so we are pretty small and the BE7K seems to be a good fit and value.
    Cheers,

  • Prime Collaboration Version: 9.0.24376 CLI root/admin Password Recovery

    Dear forum users.
    My client needs to recover both the CLI admin and root passwords for their PCA and PCP VM appliances, Version: 9.0.24376, don't ask why!
    Is the attached document the correct method to do this?

    Hi,
    I have captured from the link which says:
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/9-0/administration/guide/PC9-0AdminGuide/usermanagement.html
    We recommend that you write down the root password as it cannot be retrieved
    Resetting Prime Collaboration Assurance Passwords
    As a super administrator, system administrator or network operator, you can reset the password for other
    Prime Collaboration users.
    You can reset the Prime Collaboration Assurance web client globaladmin password using the following
    procedure.
    To reset the Prime Collaboration Assurance globaladmin password:
    Step 1
    Log in as a root user.
    Step 2
    Enter the "goemsam" command:
    Step 3
    Execute the following:
    su admin
    conf t
    username
    username password {hash|plain|remote} password role {admin|user}
    regds,
    aman

  • Cisco Prime Collaboration Usage

    Hi,
    Many Asia costumers complain it is very difficult to maintain the Cisco Collaboration system.
    So we are considering the Cisco Prime Collaboration system, see which can help or not.
    I have few questions about the Cisco Prime Collaboration Provisioning (CPCP) for SME customer / Cisco Prime Collaboration Assurance (CPCA) for Big customer.
    1. CPCP Standard version is free? one cluster? no adv. features? What is the adv. features on adv. versions?
    2. I see the CPCP will deploy the new configurations into the CM clusters, that is fine on the new CM, but the existing CM will access the CPCP push into new configurations? Any impacts will happen on delopying the new CPCP into the existing CM?
    3. CPCA lic. counted by every end devices, that is really expensive. Any cost effective methods to deploy the CPCA?
    4. If we want to monitor the TP endpoints or DX video phones, I have to plug the lan to the 37XX or above switches? 29XX cannot? 
    Medianet-Capable Devices
    Feature
    Routers
    Switches
    Cisco IOS®Software Release Supported
    Mediatrace 1.0
    Cisco 1800, 2800, 2900, 3800, 3900 Integrated Services Routers
    Cisco Catalyst® 3560E, Catalyst 3560X, 
    Catalyst 3750, 
    Catalyst 3750-Metro (only 12.2SE),
    Catalyst 3750E, and
    Catalyst 3750X
    12.2SE
    15.0SE
    15.1T
    15.1M
    IP service-level agreement (SLA) video operation
    Routers will be supported soon. Please check the feature navigator as mentioned below
    Cisco Catalyst 3560E, Catalyst 3560X, Catalyst 3750, Catalyst 3750E, and Catalyst 3750X
    12.2SE
    15.0SE

    Hi,
    Been out of the office but see that no one has yet responded to this. I can answer some of the questions.
    1. CPCP Standard version is free?
    CUCM 10+ users are entitled to use the Standard version.
     one cluster?
    Yes
     no adv. features?
    Not missing a lot, especially for smaller one cluster networks.
    What is the adv. features on adv. versions?
    The Standard and Advanced versions are pretty much the same except for the following:
    Advanced can handle multi-cluster networks
    Advanced allows administrator delegation. This means that different administrators can be assigned to different groups of end-users.
    Standard does not have advanced workflows (Approver, MAC assigner, Shipper and Receiver).
    Advanced provides a northbound API for integration to another network management application, HR system or custom UI.
    2. I see the CPCP will deploy the new configurations into the CM clusters, that is fine on the new CM, but the existing CM will access the CPCP push into new configurations?
    CPCP can push configurations to new or existing clusters. Changes made directly on a cluster will be pulled back to PCP so they stay in sync.
    Any impacts will happen on deploying the new CPCP into the existing CM?
    CPCP was designed to add to a UC network at any time. When added to an existing network, CPCP can use it's reverse sync process to import users and CM configurations.
    3. CPCA lic. counted by every end devices, that is really expensive.
    List price may appear really expensive but you need to work with a sales person to determine the actual price. There is also the option to have an enterprise license agreement which might be more cost effective if this is for a Big Customer.
    Any cost effective methods to deploy the CPCA?
    ELA as mentioned above, or use the free standard version.  It the standard version provides enough functionality, it might be an option.  Cost effective may be hard to define.  If the product significantly lowers the cost to operate the network (faster fault resolution, less administrators, usage reports, resource utilization savings, etc.) it would be cost effective.  I don't know how big the Big Customer is or what/how many endpoints/devices/apps are in the network so I cannot provide any better advice.
    I am not sure how to answer the last question so will leave it for a TME or other expert on CPCA.  It looks like a medianet question. CPCA is not completely dependent on medianet to monitor TP environments and can provide some call trace and performance without it.  This is best answered by someone on the Assurance PM/TME team.
    Regards

  • Cisco Prime Collaboration 9 cannot discover ipphone

    Hi Folks
    I am testing Cisco Prime Collaboration ver 9.0.24376 in my lab environment, Im using it to discover CUCM Cluster version 8.6.2 and successfully to obtain Server and Gateway information, but I can't see any endpoint that registered to CUCM shown on Cisco Prime Collab dashboard.
    I am also test to discover my 2nd CUCM Cluster version 9.0.1 and also successful with CUCM Server component but not for the endpoint.
    I follow this guide to ensure CUCM side already configure properly.
    http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6491/ps12363/deployment_guide_c07-723457.html#wp9000214
    Is anyone have similar problem like me ?
    Thanks
    Novriadi

    There is a specific support forum for Prime Collaboration and older UCMS management products at:
    https://supportforums.cisco.com/community/netpro/collaboration-voice-video/pcm
    I don't know if anyone from the collaboration management team monitors this page.

  • Is it possible to trigger backups of callmanagers, and application servers from prime collaboration?

    I have prime collaboration assuarance and analytics version 10.5  installed in my LAB setup. I could not see any other options other than the backup option under the administration tab; I beleive this option is to schedule and run backups for prime collaboration. Wonder if we have some options to trigger backups for call managers and other application servers...any help is much appreciated....cheers

    Hi,
    I doubt that is possible.the below link talks about
    Performing Backup and Restore for Prime Collaboration Analytics
    Prime Collaboration Analytics allows you to perform backup and restore, while you continue to use the Prime Collaboration Analytics GUI. However, until the backup is complete, the data displayed in the GUI may not be the latest.
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/10-5/analytics/guide/Cisco_Prime_Collaboration_Analytics_Guide_10-5/bk_Cisco_Prime_Collaboration_Analytics_Guide_10_chapter_011.html#task_D50DB08C00134388AE2AC30AE0536371
    regds,
    aman

  • Exchange Server 2010 Edge Transport Subscription Issue while moving Internal CA Certificate to 3rd Party Certificate

    My Client have a Exchange 2010 Organization with Single Domain Single Forest.
    They were using Internal CA Certificate and a TLS Cert.
    As a POC we are doing a POC for Exchange 2010 Hybrid Office 365 Environment.
    For this 3rd Party CA is Mandatory and they have bought a Geo Trust Certificate.
    Now when they have installed cert on both HUB as well as EDGE servers, he was prompted to do edge subscription again.
    HUB and CAS are combined on the server at both Main and DR Site.
    When they try to do edge subscription again they are getting the following error.
    SYED WASIL UDDIN Infrastructure Consultant/System Engineer Premier Systems (Pvt.) Ltd.

    I was finding out the solution and got this.
    1-Certificate will import on both EDGE and HUB Servers.
    2-Edge Sync will use Self-Sign Certificate (but I an unable to find how do I configure this)
    3-some communication between Edge and Hub will be encrypted via 3rd party Certificate.
    Could anyone suggest, which services on HUB must based in this 3rd party cert.
    All the external communication must be encrypted via 3rd party CA and communication between HUB-EDGE will set on self-sign Cert. How do I do this.
    SYED WASIL UDDIN Infrastructure Consultant/System Engineer Premier Systems (Pvt.) Ltd.
    Hi,
    Please run Get-ExchangeCertificate | fl to check your Exchange certificate settings. Also confirm if the 5E470560626E313646730C177FCA66728E2BAFF7 certificate is your trusted 3rd party cert.
    Please use Enable-ExchangeCertificate cmdlet to assign SMTP service to your self-signed certificate in your Edge server.
    Regards,
    Winnie Liang
    TechNet Community Support

  • How do you add LDAP to Prime Collaboration Provisioning?

    Hi everyone,
    Does anyone have any suggestions why the LDAP test continiously fails when adding LDAP as a resource to Prime Collaboration Provisioning 10.0?
    I'll attach a screenshot of the details that I'm using. The details are correct as using these directly from CUCM 10.5 installation works fine.
    Thanks,
    Mark

    Hi Mark,
    "Admin Distinguished name" should be the name of the user that should be present in LDAP user search scape you have provided.
    I suppose you have locally also created the same LDAP user on CPCA with different password (same passowrd doens't matter).
    Let me know whether you are still getting same issue.
    Regards,
    Praveen

Maybe you are looking for