Not recommended approach. SSL future guidelines dictates that non approved TLDs in SAN names will no longer be supported. IP address and short names in SANs is a bandaid. The proper way to to change the server name setting to the FQDN and ensure every device is getting proper DNS suffix and DNS servers.
The second problem is that Jabber doesn't just look at the tomcat. It also checks callmanager.pen which should also be signed by a valid CA using valid subject and alternate names. Sent from my Windows Phone ________________________________ From: Jason Aarons (AM)<mailto:[email protected]> Sent: 10/29/2014 1:50 PM To: cisco-voip ([email protected])<mailto:[email protected]> Subject: [cisco-voip] Callmanager TomCat Customer is asking if they can leave CallManager > CCMAdmin > Server > IP address and change the Tomcat Certificate to IP Address for Jabber for Windows client to be happy and not prompt an error first time opening? Can you even do that in CUCM? So keep the ip address as the Subject Alternate Name?
_______________________________________________ cisco-voip mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-voip
_______________________________________________ cisco-voip mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-voip
