How do I start the upgrade? Prerequisites Requirements Cisco recommends that you have knowledge of VCS/Expressway servers. The FQDN that is returned by the SRV records must match the actual FQDN of the Expressway. More details, including the process to generate the CSR, are provided in the Cisco Expressway Certificate Creation and Use Deployment Guide. My Expressway certificates are about to expire. Where can I download the Expressway upgrade image? Off-hook dialing: The way KPML dialing works between these devices and Unified CM means that you need Cisco Unified Communications Manager 10.5(2)SU2 or later. This chapter describes the best practices for configuring certificates on Cisco VCS Expressway. A vulnerability in certificate management and validation for the Mobile and Remote Access (MRA) feature for Cisco Expressway Series and TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to bypass authentication and access internal HTTP system resources. i have VCS Expressway-E (have CA certificate) and VCS Expressway-C (have certificate form CA Authority) but i did not purchase certificate for CUCM/IM & Presence. Configure Certificates on Cisco Expressway-E and Cisco VCS Expressway Configure the Trusted CA List. The VCS is not a web server. You probably don't want to use the same certificate, depending on what you will be using, that might be a very big certificate with many SAN entries that won't really make sense to have in both certificates. The VCS Expressway is configured with a traversal server zone to receive communications from the VCS Control in order to allow inbound and outbound calls to traverse the NAT device. There are three parts to the configuration: Generating a certificate signing request (CSR), Installing the SSL Server Certificate on the VCS Expressway, and Configuring the Trusted CA List on the VCS Expressway. Then generate the CSR and get the CSR signed by a CA and upload the certificate. If the VCS is known by multiple names for these purposes, such as if it is part of a cluster, this must be represented in the X.509 certificate. This document focuses on the certificate uses in Expressways. Step 3: Enter the required properties for the certificate: See Server Certificates and Clustered Systems, if your Expressway is part of a cluster. Run the following OpenSSL command to generate a new CSR and Private key for the VCS "openssl req -nodes -newkey rsa:4096 -keyout privatekey.pem -out myrequest.csr -config csrreq.cnf". We have generated a SSL certificate using a client and server certificate template on a Windows Server CA, and have uploaded this certificate to the Expressway-C and the CA chain to the Expressway-E, but the TraversalClient zone fails to form the TLS connection. The vulnerability is due to lack of proper input validation. Starting in March 2021, Cisco Webex will be moving to a new Certificate Authority, IdenTrust Commercial Root CA 1. Medium Appliances with 1 Gbps NIC - Demultiplexing Ports. Upload the public certificate to the VCS via Maintenance > Security > Server certificate webpage, "Select the server certificate file" entry box. When I check client certificate I get the following error: Invalid: unable to get certificate CRL, please ensure that you have uploaded a CRL for the CA. I have tested again the remote VCS-Expressway and no change: I can access all other boxes (VCS-Control, MCU, etc.) In this case, you need to include the public domain names in the VCS Expressway certificate as SANs. We need to renew Cisco VCS E certificate as part of security risk. Because of some firewall limitations I am in need of resolving the Expressway C fqdn directly from the Expressway E. My Cisco Expressway servers had signed the Godaddy SAN cert. You need upload signed Core certificate to Expressway-Core and signed Edge certificate in Expressway-Edge. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age. Tandberg's legacy devices typically used VCS Control, or VCS C, within the organization and VCS Expressway, or VCS E, was used between firewalls. The Expressway-E server certificate needs to include the following elements in its list of subject alternative names. To put it more simply, VCS C was used internally within the organization while VCS E was utilized externally. The documentation set for this product strives to use bias-free language. From version X12.2, Cisco VCS X8.15 or later only supports Smart Licensing and is capped at 2500 encrypted signaling sessions to endpoints. If you leave out the intermediate certificate when the Expressway-C receives the Expressway-E certificate, it cannot have a way to tie it to the trusted GoDaddy Root CA, therefore it would be rejected. In the Trusted CA Certificate Store (Maintenance --> Security certificates --> Trusted CA certificate) are around 140 public ca certificates. Facilitates connections for business-to-business, business-to-consumer, and business-to-gateway. If the Expressway / Cisco VCS cannot resolve system hostnames and IP addresses, complex deployments like MRA may not work as expected. Does the upgrade require configuration changes on Cisco Unified Communications Manager (CUCM)? If using MRA, due to security enhancement Cisco bug ID CSCvz20720, the root and intermediate certificates of the Certificate Authorities that signed Expressway-C certificate must be uploaded as "tomcat-trust" and "callmanager-trust". What must I check prior to the upgrade? Use this procedure to add the intermediate certificate CA certificate to Cisco VCS Expressway X8. Yes, there is no separate doc, that doc covers VCS and expressway. Note: We recommend you install the CA certificate first before installing the server. Is there a video to follow? Note: While this document is designed to help you with the certificate renewal process, it is a good idea to also check the Cisco Expressway Certificate Creation and Use Deployment Guide for your version. I have installed the Cisco VCS Expressway - E and Expressway -C. In some cases, root CAs will use an intermediate CA to issue certificates. It is important to note that: The SRV records return a Fully Qualified Domain Name (FQDN) and not an IP address. Definitions: Certificates are used in order to create a secure connection between two devices. Over the years I upgraded them from x6.1 to x8. The VCS Expressway has a public network domain name. I think is a problem of certificates. What is the upgrade sequence in a clustered system? Dual Interfaces and static NAT are certainly one of the items, for securing and hardening the VCS, but I'm looking beyond that and hoping the "old school" Tandberg folks have some additional best practices. If the server certificate is issued by an intermediate CA, you must add the intermediate CA certificate to the default Trusted CA list.