Mailing List Archive

Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates
Im totally looking to update all of mine I think we use digi-cert, pleasea
let us know what you find out :)
Cheers!

On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:

> Does anyone know of any public certificate authorities that have cheaper
> multi-server SAN certificate options? I had seen some in the past that let
> you buy a wildcard and then can submit CSR's against that still but having
> trouble finding that now.
>
> Trying to avoid buying 4 multi-server certificates to cover CUCM
> Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
>


--
During this time of remote work, There will be the need for connectivity to
other devices such as a cell phone. If you require assistance forwarding
your desk phone to a remote cell or message phone, please email with desk
number and where we are forwarding calls. I can do these remotely.

Johnny Q
Voice Technology Analyst II
Chemeketa Community College
Johnny.Q@chemeketa.edu
Building 22 Room 130
Work 5033995294
Cell 5035769873
FAX 5033995549
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Namecheap seems to be the cheapest option I've found from some quick
looking. They seem to resell Comodo certificates but cheaper than Comodo
offers them.

On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <
jonatan.quezada@chemeketa.edu> wrote:

> Im totally looking to update all of mine I think we use digi-cert, pleasea
> let us know what you find out :)
> Cheers!
>
> On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:
>
>> Does anyone know of any public certificate authorities that have cheaper
>> multi-server SAN certificate options? I had seen some in the past that let
>> you buy a wildcard and then can submit CSR's against that still but having
>> trouble finding that now.
>>
>> Trying to avoid buying 4 multi-server certificates to cover CUCM
>> Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
>> _______________________________________________
>> cisco-voip mailing list
>> cisco-voip@puck.nether.net
>> https://puck.nether.net/mailman/listinfo/cisco-voip
>>
>
>
> --
> During this time of remote work, There will be the need for connectivity
> to other devices such as a cell phone. If you require assistance forwarding
> your desk phone to a remote cell or message phone, please email with desk
> number and where we are forwarding calls. I can do these remotely.
>
> Johnny Q
> Voice Technology Analyst II
> Chemeketa Community College
> Johnny.Q@chemeketa.edu
> Building 22 Room 130
> Work 5033995294
> Cell 5035769873
> FAX 5033995549
>
>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Namecheap cert process is a PITA. Haven’t used them for UC servers but helped a friend with their website after they already bought them from NC.

You can only have it verify ownership with certain predefined by them emails at your domain, or dns/web.

Namecheap is a good domain registrar but I’d personally steer clear of their other services.

> On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu> wrote:
>
> ?
> Namecheap seems to be the cheapest option I've found from some quick looking. They seem to resell Comodo certificates but cheaper than Comodo offers them.
>
>> On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <jonatan.quezada@chemeketa.edu> wrote:
>> Im totally looking to update all of mine I think we use digi-cert, pleasea let us know what you find out :)
>> Cheers!
>>
>>> On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:
>>> Does anyone know of any public certificate authorities that have cheaper multi-server SAN certificate options? I had seen some in the past that let you buy a wildcard and then can submit CSR's against that still but having trouble finding that now.
>>>
>>> Trying to avoid buying 4 multi-server certificates to cover CUCM Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
>>> _______________________________________________
>>> cisco-voip mailing list
>>> cisco-voip@puck.nether.net
>>> https://puck.nether.net/mailman/listinfo/cisco-voip
>>
>>
>> --
>> During this time of remote work, There will be the need for connectivity to other devices such as a cell phone. If you require assistance forwarding your desk phone to a remote cell or message phone, please email with desk number and where we are forwarding calls. I can do these remotely.
>>
>> Johnny Q
>> Voice Technology Analyst II
>> Chemeketa Community College
>> Johnny.Q@chemeketa.edu
>> Building 22 Room 130
>> Work 5033995294
>> Cell 5035769873
>> FAX 5033995549
>>
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
It's a good thing you don't have to prove ownership for collab certs then.
I have not bought through namecheap myself, but I have witnessed the
mistake someone has made trying to get domain validated, or EV certs for
their collab gear when it's not needed, and yeah, it seemed like a hassle
and it took a few days or more.

On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com> wrote:

> Namecheap cert process is a PITA. Haven’t used them for UC servers but
> helped a friend with their website after they already bought them from NC.
>
> You can only have it verify ownership with certain predefined by them
> emails at your domain, or dns/web.
>
> Namecheap is a good domain registrar but I’d personally steer clear of
> their other services.
>
> On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu> wrote:
>
> ?
> Namecheap seems to be the cheapest option I've found from some quick
> looking. They seem to resell Comodo certificates but cheaper than Comodo
> offers them.
>
> On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <
> jonatan.quezada@chemeketa.edu> wrote:
>
>> Im totally looking to update all of mine I think we use digi-cert,
>> pleasea let us know what you find out :)
>> Cheers!
>>
>> On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:
>>
>>> Does anyone know of any public certificate authorities that have cheaper
>>> multi-server SAN certificate options? I had seen some in the past that let
>>> you buy a wildcard and then can submit CSR's against that still but having
>>> trouble finding that now.
>>>
>>> Trying to avoid buying 4 multi-server certificates to cover CUCM
>>> Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
>>> _______________________________________________
>>> cisco-voip mailing list
>>> cisco-voip@puck.nether.net
>>> https://puck.nether.net/mailman/listinfo/cisco-voip
>>>
>>
>>
>> --
>> During this time of remote work, There will be the need for connectivity
>> to other devices such as a cell phone. If you require assistance forwarding
>> your desk phone to a remote cell or message phone, please email with desk
>> number and where we are forwarding calls. I can do these remotely.
>>
>> Johnny Q
>> Voice Technology Analyst II
>> Chemeketa Community College
>> Johnny.Q@chemeketa.edu
>> Building 22 Room 130
>> Work 5033995294
>> Cell 5035769873
>> FAX 5033995549
>>
>> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
>
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
I’m using namecheap and have for years. Cheap certs from Comodo and they work fine. You can do email, web, and DNS validation - https://www.namecheap.com/support/knowledgebase/article.aspx/9637/68/how-can-i-complete-the-domain-control-validation-dcv-for-my-ssl-certificate

Sorry, I missed the part on why you’re not using an internal CA for your internal servers though?

--
-Mark
________________________________
From: cisco-voip <cisco-voip-bounces@puck.nether.net> on behalf of Anthony Holloway <avholloway+cisco-voip@gmail.com>
Sent: Monday, March 30, 2020 9:58:12 PM
To: UC Penguin <gentoo@ucpenguin.com>
Cc: cisco-voip voyp list <cisco-voip@puck.nether.net>; Jonatan Quezada <jonatan.quezada@chemeketa.edu>; Adrian Arevalo-Orozco <adrian.arevalo.orozco@chemeketa.edu>
Subject: Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates

*** EXTERNAL EMAIL - DO NOT CLICK LINKS ***

It's a good thing you don't have to prove ownership for collab certs then. I have not bought through namecheap myself, but I have witnessed the mistake someone has made trying to get domain validated, or EV certs for their collab gear when it's not needed, and yeah, it seemed like a hassle and it took a few days or more.

On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com<mailto:gentoo@ucpenguin.com>> wrote:
Namecheap cert process is a PITA. Haven’t used them for UC servers but helped a friend with their website after they already bought them from NC.

You can only have it verify ownership with certain predefined by them emails at your domain, or dns/web.

Namecheap is a good domain registrar but I’d personally steer clear of their other services.

On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:

?
Namecheap seems to be the cheapest option I've found from some quick looking. They seem to resell Comodo certificates but cheaper than Comodo offers them.

On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <jonatan.quezada@chemeketa.edu<mailto:jonatan.quezada@chemeketa.edu>> wrote:
Im totally looking to update all of mine I think we use digi-cert, pleasea let us know what you find out :)
Cheers!

On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:
Does anyone know of any public certificate authorities that have cheaper multi-server SAN certificate options? I had seen some in the past that let you buy a wildcard and then can submit CSR's against that still but having trouble finding that now.

Trying to avoid buying 4 multi-server certificates to cover CUCM Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>


--
During this time of remote work, There will be the need for connectivity to other devices such as a cell phone. If you require assistance forwarding your desk phone to a remote cell or message phone, please email with desk number and where we are forwarding calls. I can do these remotely.

Johnny Q
Voice Technology Analyst II
Chemeketa Community College
Johnny.Q@chemeketa.edu<mailto:Johnny.Q@chemeketa.edu>
Building 22 Room 130
Work 5033995294
Cell 5035769873
FAX 5033995549

_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Not to answer for Brian, but with the introduction of MRA, employees can
run Jabber on any device they want. This makes putting private ca signed
certs on those devices impossible or at least a giant headache.

On Sat, Apr 4, 2020 at 7:30 AM Mark H. Turpin <mturpin@covene.com> wrote:

> I’m using namecheap and have for years. Cheap certs from Comodo and they
> work fine. You can do email, web, and DNS validation -
> https://www.namecheap.com/support/knowledgebase/article.aspx/9637/68/how-can-i-complete-the-domain-control-validation-dcv-for-my-ssl-certificate
>
> Sorry, I missed the part on why you’re not using an internal CA for your
> internal servers though?
>
> --
> -Mark
> ------------------------------
> *From:* cisco-voip <cisco-voip-bounces@puck.nether.net> on behalf of
> Anthony Holloway <avholloway+cisco-voip@gmail.com>
> *Sent:* Monday, March 30, 2020 9:58:12 PM
> *To:* UC Penguin <gentoo@ucpenguin.com>
> *Cc:* cisco-voip voyp list <cisco-voip@puck.nether.net>; Jonatan Quezada <
> jonatan.quezada@chemeketa.edu>; Adrian Arevalo-Orozco <
> adrian.arevalo.orozco@chemeketa.edu>
> *Subject:* Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate
> Authority for CUCM certificates
>
> *** EXTERNAL EMAIL - DO NOT CLICK LINKS ***
>
> It's a good thing you don't have to prove ownership for collab certs
> then. I have not bought through namecheap myself, but I have witnessed the
> mistake someone has made trying to get domain validated, or EV certs for
> their collab gear when it's not needed, and yeah, it seemed like a hassle
> and it took a few days or more.
>
> On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com> wrote:
>
> Namecheap cert process is a PITA. Haven’t used them for UC servers but
> helped a friend with their website after they already bought them from NC.
>
> You can only have it verify ownership with certain predefined by them
> emails at your domain, or dns/web.
>
> Namecheap is a good domain registrar but I’d personally steer clear of
> their other services.
>
> On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu> wrote:
>
> ?
> Namecheap seems to be the cheapest option I've found from some quick
> looking. They seem to resell Comodo certificates but cheaper than Comodo
> offers them.
>
> On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <
> jonatan.quezada@chemeketa.edu> wrote:
>
> Im totally looking to update all of mine I think we use digi-cert, pleasea
> let us know what you find out :)
> Cheers!
>
> On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:
>
> Does anyone know of any public certificate authorities that have cheaper
> multi-server SAN certificate options? I had seen some in the past that let
> you buy a wildcard and then can submit CSR's against that still but having
> trouble finding that now.
>
> Trying to avoid buying 4 multi-server certificates to cover CUCM
> Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>
>
>
> --
> During this time of remote work, There will be the need for connectivity
> to other devices such as a cell phone. If you require assistance forwarding
> your desk phone to a remote cell or message phone, please email with desk
> number and where we are forwarding calls. I can do these remotely.
>
> Johnny Q
> Voice Technology Analyst II
> Chemeketa Community College
> Johnny.Q@chemeketa.edu
> Building 22 Room 130
> Work 5033995294
> Cell 5035769873
> FAX 5033995549
>
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>
>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Yeah. Considering how much effort we put on security, telling people to ignore cert warnings is probably not the best. It does take a bit more work. And it was ok with three year certs. Annual certs are going to make things a bit worse.

Pushing self signed certs (or roots?) to devices will be an issue. And outside the scope of telephony. There are tools that can help. I believe JoinNow tool is one example. We use that and I believe my colleague got that working in a test environment.

I’m hoping they have an SU that introduces let’s encrypt for v11.5. ????????

Sent from my iPhone

On Apr 5, 2020, at 12:00 PM, Anthony Holloway <avholloway+cisco-voip@gmail.com<mailto:avholloway+cisco-voip@gmail.com>> wrote:

Not to answer for Brian, but with the introduction of MRA, employees can run Jabber on any device they want. This makes putting private ca signed certs on those devices impossible or at least a giant headache.

On Sat, Apr 4, 2020 at 7:30 AM Mark H. Turpin <mturpin@covene.com<mailto:mturpin@covene.com>> wrote:
I’m using namecheap and have for years. Cheap certs from Comodo and they work fine. You can do email, web, and DNS validation - https://www.namecheap.com/support/knowledgebase/article.aspx/9637/68/how-can-i-complete-the-domain-control-validation-dcv-for-my-ssl-certificate

Sorry, I missed the part on why you’re not using an internal CA for your internal servers though?

--
-Mark
________________________________
From: cisco-voip <cisco-voip-bounces@puck.nether.net<mailto:cisco-voip-bounces@puck.nether.net>> on behalf of Anthony Holloway <avholloway+cisco-voip@gmail.com<mailto:avholloway%2Bcisco-voip@gmail.com>>
Sent: Monday, March 30, 2020 9:58:12 PM
To: UC Penguin <gentoo@ucpenguin.com<mailto:gentoo@ucpenguin.com>>
Cc: cisco-voip voyp list <cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>>; Jonatan Quezada <jonatan.quezada@chemeketa.edu<mailto:jonatan.quezada@chemeketa.edu>>; Adrian Arevalo-Orozco <adrian.arevalo.orozco@chemeketa.edu<mailto:adrian.arevalo.orozco@chemeketa.edu>>
Subject: Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates

*** EXTERNAL EMAIL - DO NOT CLICK LINKS ***

It's a good thing you don't have to prove ownership for collab certs then. I have not bought through namecheap myself, but I have witnessed the mistake someone has made trying to get domain validated, or EV certs for their collab gear when it's not needed, and yeah, it seemed like a hassle and it took a few days or more.

On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com<mailto:gentoo@ucpenguin.com>> wrote:
Namecheap cert process is a PITA. Haven’t used them for UC servers but helped a friend with their website after they already bought them from NC.

You can only have it verify ownership with certain predefined by them emails at your domain, or dns/web.

Namecheap is a good domain registrar but I’d personally steer clear of their other services.

On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:

?
Namecheap seems to be the cheapest option I've found from some quick looking. They seem to resell Comodo certificates but cheaper than Comodo offers them.

On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <jonatan.quezada@chemeketa.edu<mailto:jonatan.quezada@chemeketa.edu>> wrote:
Im totally looking to update all of mine I think we use digi-cert, pleasea let us know what you find out :)
Cheers!

On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:
Does anyone know of any public certificate authorities that have cheaper multi-server SAN certificate options? I had seen some in the past that let you buy a wildcard and then can submit CSR's against that still but having trouble finding that now.

Trying to avoid buying 4 multi-server certificates to cover CUCM Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>


--
During this time of remote work, There will be the need for connectivity to other devices such as a cell phone. If you require assistance forwarding your desk phone to a remote cell or message phone, please email with desk number and where we are forwarding calls. I can do these remotely.

Johnny Q
Voice Technology Analyst II
Chemeketa Community College
Johnny.Q@chemeketa.edu<mailto:Johnny.Q@chemeketa.edu>
Building 22 Room 130
Work 5033995294
Cell 5035769873
FAX 5033995549

_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Last I looked, SSL certs can be had for 2 years, so agreed, not as good as
3, but still.

I'm a big fan of Let's Encrypt, but putting that on the inside of your
network will be challenging, since that whole process has to be accessed
from the internet for it to work. I do hope they solve it for CUCM, CUC
and IM&P, but I don't see it happening anytime soon.

When you setup LE on the Expressway Edge, it has to be accessed by port 80
for them to validate it, no security engineer is going to let you do that
to CUCM, unless they work up a method to do some other validation.

On Sun, Apr 5, 2020 at 11:28 AM Lelio Fulgenzi <lelio@uoguelph.ca> wrote:

> Yeah. Considering how much effort we put on security, telling people to
> ignore cert warnings is probably not the best. It does take a bit more
> work. And it was ok with three year certs. Annual certs are going to make
> things a bit worse.
>
> Pushing self signed certs (or roots?) to devices will be an issue. And
> outside the scope of telephony. There are tools that can help. I believe
> JoinNow tool is one example. We use that and I believe my colleague got
> that working in a test environment.
>
> I’m hoping they have an SU that introduces let’s encrypt for v11.5. ????????
>
> Sent from my iPhone
>
> On Apr 5, 2020, at 12:00 PM, Anthony Holloway <
> avholloway+cisco-voip@gmail.com> wrote:
>
> Not to answer for Brian, but with the introduction of MRA, employees can
> run Jabber on any device they want. This makes putting private ca signed
> certs on those devices impossible or at least a giant headache.
>
> On Sat, Apr 4, 2020 at 7:30 AM Mark H. Turpin <mturpin@covene.com> wrote:
>
>> I’m using namecheap and have for years. Cheap certs from Comodo and they
>> work fine. You can do email, web, and DNS validation -
>> https://www.namecheap.com/support/knowledgebase/article.aspx/9637/68/how-can-i-complete-the-domain-control-validation-dcv-for-my-ssl-certificate
>>
>> Sorry, I missed the part on why you’re not using an internal CA for your
>> internal servers though?
>>
>> --
>> -Mark
>> ------------------------------
>> *From:* cisco-voip <cisco-voip-bounces@puck.nether.net> on behalf of
>> Anthony Holloway <avholloway+cisco-voip@gmail.com>
>> *Sent:* Monday, March 30, 2020 9:58:12 PM
>> *To:* UC Penguin <gentoo@ucpenguin.com>
>> *Cc:* cisco-voip voyp list <cisco-voip@puck.nether.net>; Jonatan Quezada
>> <jonatan.quezada@chemeketa.edu>; Adrian Arevalo-Orozco <
>> adrian.arevalo.orozco@chemeketa.edu>
>> *Subject:* Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate
>> Authority for CUCM certificates
>>
>> *** EXTERNAL EMAIL - DO NOT CLICK LINKS ***
>>
>> It's a good thing you don't have to prove ownership for collab certs
>> then. I have not bought through namecheap myself, but I have witnessed the
>> mistake someone has made trying to get domain validated, or EV certs for
>> their collab gear when it's not needed, and yeah, it seemed like a hassle
>> and it took a few days or more.
>>
>> On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com> wrote:
>>
>> Namecheap cert process is a PITA. Haven’t used them for UC servers but
>> helped a friend with their website after they already bought them from NC.
>>
>> You can only have it verify ownership with certain predefined by them
>> emails at your domain, or dns/web.
>>
>> Namecheap is a good domain registrar but I’d personally steer clear of
>> their other services.
>>
>> On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu> wrote:
>>
>> ?
>> Namecheap seems to be the cheapest option I've found from some quick
>> looking. They seem to resell Comodo certificates but cheaper than Comodo
>> offers them.
>>
>> On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <
>> jonatan.quezada@chemeketa.edu> wrote:
>>
>> Im totally looking to update all of mine I think we use digi-cert,
>> pleasea let us know what you find out :)
>> Cheers!
>>
>> On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu> wrote:
>>
>> Does anyone know of any public certificate authorities that have cheaper
>> multi-server SAN certificate options? I had seen some in the past that let
>> you buy a wildcard and then can submit CSR's against that still but having
>> trouble finding that now.
>>
>> Trying to avoid buying 4 multi-server certificates to cover CUCM
>> Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
>> _______________________________________________
>> cisco-voip mailing list
>> cisco-voip@puck.nether.net
>> https://puck.nether.net/mailman/listinfo/cisco-voip
>> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>>
>>
>>
>> --
>> During this time of remote work, There will be the need for connectivity
>> to other devices such as a cell phone. If you require assistance forwarding
>> your desk phone to a remote cell or message phone, please email with desk
>> number and where we are forwarding calls. I can do these remotely.
>>
>> Johnny Q
>> Voice Technology Analyst II
>> Chemeketa Community College
>> Johnny.Q@chemeketa.edu
>> Building 22 Room 130
>> Work 5033995294
>> Cell 5035769873
>> FAX 5033995549
>>
>> _______________________________________________
>> cisco-voip mailing list
>> cisco-voip@puck.nether.net
>> https://puck.nether.net/mailman/listinfo/cisco-voip
>> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>>
>> _______________________________________________
>> cisco-voip mailing list
>> cisco-voip@puck.nether.net
>> https://puck.nether.net/mailman/listinfo/cisco-voip
>> <https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
>>
>> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
>
> _______________________________________________
> cisco-voip mailing list
> cisco-voip@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-voip
>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Sure, two year certs available. But browsers are making the move to not trust anything greater than 13 months if issues after a certain date. That’s the thing that has put much of system admin world up in arms.

https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/

Sent from my iPhone

On Apr 5, 2020, at 12:44 PM, Charles Goldsmith <w@woka.us<mailto:w@woka.us>> wrote:

Last I looked, SSL certs can be had for 2 years, so agreed, not as good as 3, but still.

I'm a big fan of Let's Encrypt, but putting that on the inside of your network will be challenging, since that whole process has to be accessed from the internet for it to work. I do hope they solve it for CUCM, CUC and IM&P, but I don't see it happening anytime soon.

When you setup LE on the Expressway Edge, it has to be accessed by port 80 for them to validate it, no security engineer is going to let you do that to CUCM, unless they work up a method to do some other validation.

On Sun, Apr 5, 2020 at 11:28 AM Lelio Fulgenzi <lelio@uoguelph.ca<mailto:lelio@uoguelph.ca>> wrote:
Yeah. Considering how much effort we put on security, telling people to ignore cert warnings is probably not the best. It does take a bit more work. And it was ok with three year certs. Annual certs are going to make things a bit worse.

Pushing self signed certs (or roots?) to devices will be an issue. And outside the scope of telephony. There are tools that can help. I believe JoinNow tool is one example. We use that and I believe my colleague got that working in a test environment.

I’m hoping they have an SU that introduces let’s encrypt for v11.5. ????????

Sent from my iPhone

On Apr 5, 2020, at 12:00 PM, Anthony Holloway <avholloway+cisco-voip@gmail.com<mailto:avholloway+cisco-voip@gmail.com>> wrote:

Not to answer for Brian, but with the introduction of MRA, employees can run Jabber on any device they want. This makes putting private ca signed certs on those devices impossible or at least a giant headache.

On Sat, Apr 4, 2020 at 7:30 AM Mark H. Turpin <mturpin@covene.com<mailto:mturpin@covene.com>> wrote:
I’m using namecheap and have for years. Cheap certs from Comodo and they work fine. You can do email, web, and DNS validation - https://www.namecheap.com/support/knowledgebase/article.aspx/9637/68/how-can-i-complete-the-domain-control-validation-dcv-for-my-ssl-certificate

Sorry, I missed the part on why you’re not using an internal CA for your internal servers though?

--
-Mark
________________________________
From: cisco-voip <cisco-voip-bounces@puck.nether.net<mailto:cisco-voip-bounces@puck.nether.net>> on behalf of Anthony Holloway <avholloway+cisco-voip@gmail.com<mailto:avholloway%2Bcisco-voip@gmail.com>>
Sent: Monday, March 30, 2020 9:58:12 PM
To: UC Penguin <gentoo@ucpenguin.com<mailto:gentoo@ucpenguin.com>>
Cc: cisco-voip voyp list <cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>>; Jonatan Quezada <jonatan.quezada@chemeketa.edu<mailto:jonatan.quezada@chemeketa.edu>>; Adrian Arevalo-Orozco <adrian.arevalo.orozco@chemeketa.edu<mailto:adrian.arevalo.orozco@chemeketa.edu>>
Subject: Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates

*** EXTERNAL EMAIL - DO NOT CLICK LINKS ***

It's a good thing you don't have to prove ownership for collab certs then. I have not bought through namecheap myself, but I have witnessed the mistake someone has made trying to get domain validated, or EV certs for their collab gear when it's not needed, and yeah, it seemed like a hassle and it took a few days or more.

On Mon, Mar 30, 2020 at 4:40 PM UC Penguin <gentoo@ucpenguin.com<mailto:gentoo@ucpenguin.com>> wrote:
Namecheap cert process is a PITA. Haven’t used them for UC servers but helped a friend with their website after they already bought them from NC.

You can only have it verify ownership with certain predefined by them emails at your domain, or dns/web.

Namecheap is a good domain registrar but I’d personally steer clear of their other services.

On Mar 30, 2020, at 14:57, Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:

?
Namecheap seems to be the cheapest option I've found from some quick looking. They seem to resell Comodo certificates but cheaper than Comodo offers them.

On Mon, Mar 30, 2020 at 2:45 PM Jonatan Quezada <jonatan.quezada@chemeketa.edu<mailto:jonatan.quezada@chemeketa.edu>> wrote:
Im totally looking to update all of mine I think we use digi-cert, pleasea let us know what you find out :)
Cheers!

On Mon, Mar 30, 2020 at 11:43 AM Brian Meade <bmeade90@vt.edu<mailto:bmeade90@vt.edu>> wrote:
Does anyone know of any public certificate authorities that have cheaper multi-server SAN certificate options? I had seen some in the past that let you buy a wildcard and then can submit CSR's against that still but having trouble finding that now.

Trying to avoid buying 4 multi-server certificates to cover CUCM Tomcat/Unity Connection Tomcat/UCCX Tomcat/IM&P XMPP.
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>


--
During this time of remote work, There will be the need for connectivity to other devices such as a cell phone. If you require assistance forwarding your desk phone to a remote cell or message phone, please email with desk number and where we are forwarding calls. I can do these remotely.

Johnny Q
Voice Technology Analyst II
Chemeketa Community College
Johnny.Q@chemeketa.edu<mailto:Johnny.Q@chemeketa.edu>
Building 22 Room 130
Work 5033995294
Cell 5035769873
FAX 5033995549

_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip<https://nam10.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpuck.nether.net%2Fmailman%2Flistinfo%2Fcisco-voip&data=01%7C01%7Cmturpin%40covene.com%7C58b306e13bf84d8d65de08d7d51fd22a%7C575b0cc755204e999cb37affbf511f45%7C1&sdata=31dWW3cRzojiu8GNDZSHJbkachrakSZSm9SIDE2cljo%3D&reserved=0>
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip
_______________________________________________
cisco-voip mailing list
cisco-voip@puck.nether.net<mailto:cisco-voip@puck.nether.net>
https://puck.nether.net/mailman/listinfo/cisco-voip
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
You've received an encrypted message from mturpin@covene.com
To view your messageSave and open the attachment (message.html), and follow the instructions.Sign in using the following email address: cisco-voip@puck.nether.net


This email message and its attachments are for the sole use of the intended recipient or recipients and may contain confidential information. If you have received this email in error, please notify the sender and delete this message.


Message encryption by Microsoft Office 365
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
What is this encrypt3d m3ssage?

ROT-13 encoding only please. :)

Sent from my iPhone

On Apr 5, 2020, at 1:18 PM, Mark H. Turpin <mturpin@covene.com<mailto:mturpin@covene.com>> wrote:


You've received an encrypted message from mturpin@covene.com
To view your message
Save and open the attachment (message.html), and follow the instructions.
Sign in using the following email address: lelio@uoguelph.ca



This email message and its attachments are for the sole use of the intended recipient or recipients and may contain confidential information. If you have received this email in error, please notify the sender and delete this message.



<mime-attachment.png> Message encryption by Microsoft Office 365

<message.html>
Re: [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates [ In reply to ]
Oh that's awesome. *face palm*

________________________________
From: Lelio Fulgenzi <lelio@uoguelph.ca>
Sent: Sunday, April 5, 2020 12:23 PM
To: Mark H. Turpin <mturpin@covene.com>
Cc: Anthony Holloway <avholloway+cisco-voip@gmail.com>; cisco-voip voyp list <cisco-voip@puck.nether.net>; Jonatan Quezada <jonatan.quezada@chemeketa.edu>; Adrian Arevalo-Orozco <adrian.arevalo.orozco@chemeketa.edu>
Subject: Re: [cisco-voip] [EXTERNAL] Cost-Effective Public Certificate Authority for CUCM certificates

*** EXTERNAL EMAIL - DO NOT CLICK LINKS ***


What is this encrypt3d m3ssage?

ROT-13 encoding only please. :)

Sent from my iPhone

On Apr 5, 2020, at 1:18 PM, Mark H. Turpin <mturpin@covene.com<mailto:mturpin@covene.com>> wrote:


You've received an encrypted message from mturpin@covene.com
To view your message
Save and open the attachment (message.html), and follow the instructions.
Sign in using the following email address: lelio@uoguelph.ca



This email message and its attachments are for the sole use of the intended recipient or recipients and may contain confidential information. If you have received this email in error, please notify the sender and delete this message.



<mime-attachment.png> Message encryption by Microsoft Office 365

<message.html>