[cisco-voip] CIMC MIC self-signed cert and new browsers

2019-08-28 Thread Dana Tong
Hi all, New server install. Trying to login to the CIMC to configure. Chrome, Firefox, IE all have a hissy fit. I did manage to get in once on one of the servers using firefox and dropping the max TLS version to 3. But after setting the password and change IP and hostname, it won't let me back

Re: [cisco-voip] PSA: Hunt Groups and Alerting Names

2019-08-28 Thread Anthony Holloway
Update: I tried to use this solution on an 11.5(1)SU6 system, and it didn't work. This is not great, but neither is the original issue. When I looked at the Call-Info header, it was different that the 11.5(1)SU5 system I tested on. The %22 was not in the header, rather it looked like this:

Re: [cisco-voip] Bug Search Code Injection

2019-08-28 Thread Brian Meade
I would keep pushing this. There is an internal review process for bug release notes but clearly they failed here. That should not be the only thing keeping Cisco employees from potentially putting malicious code in bug notes. The reviewers probably wouldn't even be able to tell what is

Re: [cisco-voip] PRI Inbound and Two-Stage Dialing

2019-08-28 Thread Anthony Holloway
Bump On Mon, Aug 26, 2019 at 10:50 AM Anthony Holloway < avholloway+cisco-v...@gmail.com> wrote: > A few years ago, Cisco introduced us to the Toll Fraud prevention changes > in 15.1(2)T > , and > one of the changes was dealing

Re: [cisco-voip] Bug Search Code Injection

2019-08-28 Thread Anthony Holloway
Here is the response I got back after Cisco looked into my report: *"And as CDETS is not accessible to external users no malicious code can be entered and internal users will not enter any malicious code."* On Thu, Aug 22, 2019 at 10:02 AM Anthony Holloway < avholloway+cisco-v...@gmail.com>