Unity Connection - Certificate from cucm no more trusted for encrypted calls after upgrade to 10.5(1)

Hello Support Community,
i have a strange problem:
after upgrading my cucm and unity connection from 9.1 to 10.5(1) enctrypted calls are no more working.
situation 1: CUCM is down, Subscriber is up: Encrypted call to Unity Connection work correctly
situation 2: CUCM is up: Encrypted Calls to Unity Connection not working.
i get the following Info in the log for the Connection Conversion Manager:
19:35:21.053 |15865,,,MiuGeneral,25,Invalid Certificate: Received Certificate -----BEGIN CERTIFICATE-----
MIID8zCCAtugAwIBAgIQc/fBdUz1Zdh4CXhcPqGVuDANBgkqhkiG9w0BAQsFADBw
MQswCQYDVQQGEwJERTELMAkGA1UEChMCSVQxGzAZBgNVBAsTEkhlbGxnYXRlIFRl
XD0oD9d5MQ==
-----END CERTIFICATE-----
 doesn't match with stored Certificate: -----BEGIN CERTIFICATE-----
MIIC2DCCAkGgAwIBAgIIJWCm4bSdt+kwDQYJKoZIhvcNAQEFBQAw
-----END CERTIFICATE-----
so where does Unity Connection cache this certificate and how can i delete/replace it?
the cert shown in the logs is the one from cucm: ("CallManager"), i recreated it through cucm os administration, now i see the same error message on unity connection for the new recreated certificate.

Actually It doesn't. It says he's on a MacBook. I don't know all the different types of Macs. I was having a ton of problems with iChat. I opened DMZ to my computer, knocked down all firewalls etc and left everything exposed, still with bad results. A few weeks ago my power supply went out on my D-Link. I bought a linksys. Since I'd left all firewalls off I figured it couldn't be the router. I power cycled everything n the netork, still no luck. Today I bought a universal Power supply and started up my D-Link Router. Everything worked perfectly. My wifes computer - a laptop running Tiger worked fine with the Linksys and did my machine before the Leopard upgrade. Now that I've got the D-Link online everythings working.
Message was edited by: graphico
Message was edited by: graphico

Similar Messages

  • Unity Connection 10.5.1: I upgraded the Unity Connection Server from V 9.1. After that, cannot logn to ELM an error message " The server encountered an internal error that prevented it from fulfilling this request." appears

    Unity Connection 10.5.1: I upgraded the Unity Connection Server from V 9.1. After that, cannot logn to ELM an error message " The server encountered an internal error that prevented it from fulfilling this request." appears. The error further displays "
    type: Exception report
    message:
    description: The server encountered an internal error that prevented it from fulfilling this request.
    exception:
    ServletException Could not initialize class com.cisco.vos.platform.api.config.UpgradeStatus
    root cause:
    NoClassDefFoundError Could not initialize class com.cisco.vos.platform.api.config.UpgradeStatus
    note: The full stack trace of the root cause is available in the logs.
    Has anyone experience this issue? Any solutions? Your assistance is greatly appreciated!

    Hi Mesut,
    you can refer the link for migration
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/10x/upgrade/guide/10xcucrugx/10xcucrug010.html
    regds,
    aman

  • Unity Connection 8.5 - No Diversion Header information in transfered call

    We are having call failures when calls are transfered to our SIP provider from Unity Connection (AutoAttendent). We have tracked this down to Unity is sending a Refer that does not have any information regarding the number the call was transfered from. Subsequently Callmanager does not create a diversion header in the invite to the SIP provider.
    The SIP provider require either a authorized number in the from header or a the same in the diversion header.
    We have the rediversion headers enabled on the callmanager side of the trunk.
    Does anyone have end to end SIP configuration with UCM 8.5 and Unity Connection 8.5 and can complete transfers back to the provider?
    mike

    I don't see any problem, just don't check the option to ignore additional input when configuring caller input on digit 1
    By default CUC will give you 1500 ms to dial for any other digits before trying to route the call with whatever you dialed.
    HTH
    java
    if this helps, please rate
    www.cisco.com/go/pdihelpdesk

  • New self signed certificate, how to mark as trusted for all users on clients

    We have a new 10.8 server that we are currently using for iChat/Messages service.  We have created a self signed certificate to encrypt the traffic to the Messages service since we have the service accessible for internet and phone users.  We use network accounts and users need to log in on several different machines when in the office.
    Can anyone suggest how to tell a client machine to trust the certificate for all users?
    Currently, each user is asked to trust the certificate on each client they log into.
    I have imported the server certificate into the client's system keychain in Kechain Access and asked it to trust the certificate for all items manually.  This does not appear to allow all users to trust the certificate since subsequent users who have not yet trusted the certificate on the test client are still asked to confirm trust.  When opening the iChat.app the users are still propmpted to verify the certificate which now indicates that it is trusted for all users.

    Resolved.
    - Drag certificate from verification dialog.
    - Import into System Keychain
    - Select certificate in System Keychain and select "i" button at bottom of window.
    - Set all items to always trust.

  • Unity Connection 8.5(1) API SOAP AXL for Voicemail PIN Resets?

    I'm trying to locate a URL to read up on the Unity Connection 8.5 APIs , I have a web developer who wants to write a in-house self service web page that allows users to reset a subscirbers own TUI voicemail PIN. He's a programmer, I am not, but I see references to the Unity SOAP AXL APIs that could be used for such.

    You're looking for the Cisco Unity Connection Provisioning Interface (CUPI). They have a WADL and XML schema for the API posted which I understand to be useful to those programmers.
    Specifically to what this customer wants, the DocWiki has a section on Changing Passwords through the CUPI.
    Please rate useful posts.

  • CUCM-VCS Integration VCS B2BUA Encryption Call Failures

    All,
    I have the following scenario:
    CUCM 9.1.2SU1
    VCS X8.1.1
    MX300 endpoints (CUCM registered) 
    We are not running in mixed mode on CUCM
    We want media streams with external call parties to be encrypted. We do have TLS end-to-end but I don't believe we can support SRTP to the MX300s registered to UCM w/o provisioning mixed mode (based on Cisco docs). So, we are attempting to use Media encryption policy on the VCS. Specifically, we set one of the traversal client zone to use "Best effort". This works for most calls but we have seen a couple of calls fail.
    From end user perspective, failures manifest as a call that gets connected and is immediately torn down. 
    On the VCS, we will see the following when looking at the call history:
    The B2BUA Encryption component is disconnected after ~3 seconds. The disconnect reason is: B2BUA disconnected call on the ingress saying "mismatched transport type in answer".
    Based on context clues, this points to TLS negotiation. The thing is, if I set the media policy back to "auto" then the call connects fine and the transport is TLS. At least, it reports TLS on my VCS-C and VCS-E.
    Any pointers that someone is willing to toss my way?
    Thanks in advance,
    Bill (@ucguerrilla)

    Won't help but I have a very similar but slightly different scenario with:
    CUCM 9.1
    VCS 8.2.2
    Jabber 10 or CUCM registered TC endpoint
    As for settings:
    CUCM-VCS SIP trunk is TCP not encrypted (never got it to work following the doc step by step....)
    VCS-C to VCS-E is TLS as setup on the doc.
    On the VCS-C, the DNSZone Media Encrytion mode is set to "Auto"
    Some SIP calls work perfectly (i.e. the Cisco test endpoints) but some users have issues. Dialing partners' cloud service video-conference, the call connects and gets dropped immediately. I created myself a trial account on that service to test and can reproduce it all the time. I can see the call coming in my cloud service client and when I accept it it just drops.
    On the VCS-C,
    I see a SIP 200 OK
    an then a call component status=disconnected  type=B2BUA
    State
    Inactive
    Start time
    2014-11-11 16:51:22
    Duration
    5 seconds
    Disconnect reason summary
    disconnected
    Disconnect reason details
    B2BUA disconnected call on the Egress saying "Received 'Request Timeout' to mid-dialog request"
    But on the VCS-E in the call history, I only see and "408 request timeout".
    When I call my Jabber account from that service it works well. But in that case the second call component with type B2BUA shows:
    State
    Inactive
    Start time
    2014-11-11 17:14:02
    Duration
    40 seconds
    Disconnect reason summary
    BYE
    Disconnect reason details
    Egress disconnected call
    Tag
    3d14cee5-01ad-4468-9e3b-e0925dde15d4
    Box call serial number
    1bc2473f-2a09-4dea-8ffd-a7e88a3ef05b
    Have also no clue of what is happening

  • Unable to connect to Oracle db v 9.2.0.1.0 after upgrading to Windows 2003

    Hello, I am working on a java enterprise application that accesses Oracle DB version 9.2.0.1.0. It was working until I upgraded the operating system from Windows 2000 server to Windows 2003 server enterprise edition. the db connection is lost sometimes when accessing the db for long time so i have to close the session and open a new one. also the batch file (wfjvlsnr.bat) that resides under (Oracle_Home\ora92\wf\admin) can not connect to the db with the user name (owf_mgr) after upgrading to Windows 2003 although it was working on Windows 2000 server....
    Could you sujjest any solution for this problem?
    Thanks....

    Are you talking about upgrading the client operating system? Or the server operating system? The first version of the Oracle database that was supported on Windows 2003 was 9.2.0.3, so if you upgraded the server operating system, you'll need to apply an appropriate database patchset.
    Justin
    Distributed Database Consulting, Inc.
    http://www.ddbcinc.com/askDDBC

  • Performance problem for mass transactions after upgrade from 4.7 to ECC6.0

    Hi All,
    After upgrade from 4.7 to ECC 6.0 (IS-U), mass transactions such as FPY1, FPVA, FP04M are taking very long time to complete. for example, before upgrade the jobs sceduled for FPVA transaction take around 5k-6k seconds. Whereas after upgrade the jobs for FPVA with the same variant takes around 9k-10k seconds. I am unable to figure out the cause for exponential increase in the duration of several mass-jobs (after the upgrade). Are there any SAP notes or do we need to do any customizing setting to solve this problem? Does anyone face this kind of problem?
    Thanks in advance
    Taj

    Hi,
    This is normal after upgrade to 6.0, I have faced the same in all upgrades I've done and some others that I have involved also. If you did not requests and going live upgrade check I strongly recomend to schedule an Early Watch Check to minimize the impact. Times won´t be the same but can be very close if the system is tuned well. We have tuned systems that now run with good performance after this services.

  • Any more update for Nokia N8 after belle refresh??...

    Hello guys...great work on your part for providing new updates for nokia n8.... Its really great on your part...now my phone is fantastic...
    Just wanted to know if Nokia is planning to release new updates for the N8, after Belle Refresh??
    If new updates are coming in the near future,please do let us know sir.
    From- Nokia N8 lover.

    @GEN82012, this is probably the wrong thread for enquiring on updates but...
    No you can't download directly from Nokia if the update hasn't been released for your product code.
    Updates are by Product Code, type *#0000# on the Call screen. For example mine is 059C7R0.
    These codes are country and operator specific.
    Be aware there is a difference between a "Vanilla" handset brought directly from Nokia and an "Unlocked" one.
    If a carrier "Unlocks" the handset it means you can use it on other networks but the Product Code will remain the original one and can't be changed.
    If the phone has been repaired at some stage it may have a non standard board in it as well and I think those can only be updated at Nokia Care.
    If you take the phone to Nokia Care with proof that it is legally unlocked they may be willing to load the local "Vanilla" variant for you.
    Note; mine has recently updated to  111.040.1511.
    N95 (RM159) V31.0.017, N8 (RM596) Belle 111.040.1511

  • CUCM sending e-mails for missed calls..

    We are waiting for a solution to get missed calls to exchange/outlook - like other vendors ( Siemens or MS-OCS with the ESTOS GW ) who can deliver such urgent needed features. Or is there a solution from Cisco already in place ?

    Hi Patrick,
    thanks for your response.
    We have already OCS with RCC in place. But its like with CUPC. We get only information for missed calls on Computers when the client is running. This is true for MOC and for CUPC. The problem is for users who are on tour and want to look into a computer system for missed calls. This can be Outlook or another system which they can access from remote. This could be the also the webinterface of the Ciscop IP Phone. But there is no authentication nor Call history implemented.

  • Cannot 'Unmark Blank' for FIB Questions after Upgrade from CP4 to CP5 (Fill in the Blank)

    Hi Everyone!
    I'm having trouble editing a fill in the blank question that was upgraded from CP4 to CP5.
    The problems is I cannot see where the blank is.  Not the blank in my sentence, I have that, but the entry box. When running the course the blanks are at the TOP LEFT corner fo the slide.
    but when creating the course I can't see where the blanks are, to move them.....
    So to Troubleshoot, I thought I'd re-construct the answers, I clicked the sentence, and clicked unmark ... but it does not unmark....
    <EDIT> Okay I got it to unmark, sorta, but not really. Now I have three answer boxes on the test in run mode, but cant see ANY in CP5 when building it. </EDIT>
    Hmmmmm
    Anyone got ideas?
    (re-constructing the question on a new slide is not desired, I have hundres of questions, considering my 30 courses.
    Thank you!
    Greg

    Hello,
    Sorry, but I do not understand your question quite well, it is an editing issue when upgrading. Perhaps it would help if you posted some screenshots?
    And to be sure: did you install the patch for CP5 released in December?
    Lilybiri

  • How do I keep my profiles from being wiped and substituted by default profile after upgrade

    Linux, openSuse 13.1. After setting up 9 profiles that I need to do my work, an upgrade wiped each custom profile and filled it with the firefox default, how do I stop this behavior.

    These add-ons can be a great help by backing up and restoring Firefox
    '''[https://addons.mozilla.org/en-US/firefox/addon/febe/?src=collection&collection_id=33bf10fa-666d-45a2-9bc9-491ce21671c6 FEBE (Firefox Environment Backup Extension)]''' {web link}
    FEBE allows you to quickly and easily backup your
    Firefox extensions, history, passwords, and more.
    In fact, it goes beyond just backing up -- It will actually rebuild
    your saved files individually into installable .xpi files.
    It will also make backup of files that you choose.
    '''[https://addons.mozilla.org/en-US/firefox/addon/opie/?src=collection&collection_id=33bf10fa-666d-45a2-9bc9-491ce21671c6 OPIE]''' {web link}
    Import/Export extension preferences

  • No more scanning HP LaserJet 3020 after upgrading to MacOS X 10.10 Yosemite

    The device still prints.
    Scanner device: You can not open the application "HP Scan" because PowerPC applications are no longer supported.
     Systemversion: OS X 10.10.1 (14B25)
      Kernel-Version: Darwin 14.0.0
      Startvolume: Macintosh HD

    Hi,
    I afraid that scanning is no longer supported on some of the latest OS for a while...
    Although it might still worked on previous versions it is likely to cause issues on Yosemite, it is no longer officially supported since OS X 10.7 (Lion):
    http://h20564.www2.hp.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03411613#N100BA
    Shlomi
    Say thanks by clicking the Kudos thumb up in the post.
    If my post resolve your problem please mark it as an Accepted Solution

  • Wt do u think guys there would be no more updates for ipad ios after 5.1.1

    wt will i do with my ipad after 1 yr. if i dont get ios updated there would be hardly any application in the appstore for 5.1.1 no?

    shanks29 wrote:
    if i dont get ios updated there would be hardly any application in the appstore for 5.1.1 no?
    It will probably be quite some time before all apps require iOS 6. And, as long as you have the older versions of the apps on your iPad, you will probably be fine.

  • How disable the home botton from taking picture every time it is pushed after upgrade iPad one with the new software

    How to disable home botton to take pictures

    Try a reset. Hold the Sleep and Home button down for about 10 seconds until you see the Apple logo.

Maybe you are looking for

  • BB Link with Q10 no longer working on Windows 8

    Mobile carrier:  Bell Mobility Model info and OS version:  Q10, 10.1.0.238 Blackberry Link version: 1.1.0.37 Free space: 9.7 Gb Battery pull: Battery pull did not resolve issue Factory reset:  I would like to explore all of my other options before bl

  • To convert date dd/mm/yyyy in Timestamp format

    hi I want to convert date of format dd/MM/yyyy, which get from user by PropertyUtils.getSimplePropetrty(form, "startDate"); , into Timestamp format........... please help me in this regard....... 1904

  • Can I insert ActiveX controls in Web Dynpro Java?

    We want to insert ActiveX controls in Web Dynpro 7.3. Is it possible?

  • I phone photo time & date details ?

    How do I find the time and date details for photos I have taken please ? Can find the exact geographical location but no date or time details. Thanks

  • Adobe Flash CS5 Pro failed to install?

    Every time I try to install Flash Pro CS5 on my laptop, it always fails. This is my error log: Please Insert Flash Pro Disk .. p.s: Exit Code: 24 -------------------------------------- Summary -------------------------------------- - 0 fatal error(s)