nerdexam
Cisco

300-820 · Question #231

Refer to the exhibit. A Cisco UCM cluster in mixed mode is integrated with Cisco Expressway-C for Mobile and Remote Access endpoint registration. TLS verify mode is enabled and self-signed…

The correct answer is D. The Expressway-C does not allow two self-signed certificates with the same CN to be trusted. E. The Call Manager certificate is causing a conflict. Cisco Expressway-C does not support two self-signed certificates with the same Common Name (CN). Since both the CallManager and Tomcat certificates use the same CN and are self-signed, this creates a trust issue, especially with TLS verify mode enabled. The CallManager…

Mobile and Remote Access

Question

Refer to the exhibit. A Cisco UCM cluster in mixed mode is integrated with Cisco Expressway-C for Mobile and Remote Access endpoint registration. TLS verify mode is enabled and self-signed certificates with the same common name for Cisco Tomcat and Cisco Call Manager are uploaded to Expressway-C. A Cisco Jabber client fails to register by using secure SIP. Which two configurations are the cause of the issue? (Choose two.)

Exhibit

300-820 question #231 exhibit

Options

  • AThe Tomcat certificate has the incorrect FQDN for the Cisco UCM server.
  • BThe incorrect secure device profile was applied to the Jabber client.
  • CThe Jabber client cannot connect to its associated phone device by using Cisco Computer
  • DThe Expressway-C does not allow two self-signed certificates with the same CN to be trusted.
  • EThe Call Manager certificate is causing a conflict.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    17% (4)
  • C
    4% (1)
  • D
    74% (17)

Explanation

Cisco Expressway-C does not support two self-signed certificates with the same Common Name (CN). Since both the CallManager and Tomcat certificates use the same CN and are self-signed, this creates a trust issue, especially with TLS verify mode enabled. The CallManager certificate conflict arises because Expressway-C cannot differentiate between two certificates with the same CN when verifying TLS, causing secure SIP registration to fail. To resolve this, use certificate authority (CA)-signed certificates with unique CNs for each service or use different FQDNs per certificate.

Topics

#Mobile and Remote Access#Expressway-C#Certificate Management#Cisco Unified Communications Manager

Community Discussion

No community discussion yet for this question.

Full 300-820 Practice