Not recommended approach. SSL future guidelines dictates that non approved TLDs 
in SAN names will no longer be supported. IP address and short names in SANs is 
a bandaid. The proper way to to change the server name setting to the FQDN and 
ensure every device is getting proper DNS suffix and DNS servers.

The second problem is that Jabber doesn't just look at the tomcat. It also 
checks callmanager.pen which should also be signed by a valid CA using valid 
subject and alternate names.

Sent from my Windows Phone
________________________________
From: Jason Aarons (AM)<mailto:[email protected]>
Sent: ‎10/‎29/‎2014 1:50 PM
To: cisco-voip ([email protected])<mailto:[email protected]>
Subject: [cisco-voip] Callmanager TomCat

Customer is asking if they can leave CallManager > CCMAdmin > Server >  IP 
address and change the Tomcat Certificate to IP Address for Jabber for Windows 
client to be happy and not prompt an error first time opening?  Can you even do 
that in CUCM? So keep the ip address as the Subject Alternate Name?





_______________________________________________
cisco-voip mailing list
[email protected]
https://puck.nether.net/mailman/listinfo/cisco-voip
_______________________________________________
cisco-voip mailing list
[email protected]
https://puck.nether.net/mailman/listinfo/cisco-voip

Reply via email to