Guide · in research
Setting up multi-server SAN certificates in Unified CM and IM and Presence
Verified 2026-10-02 · 69 sources · tier 2
In research. This guide has not been written yet. It has 69 sources to build on.
See also
Configures
- Cisco unified cm — Certificate management in Cisco Unified OS Administration on Unified CM and IM and Presence nodes.
Related to
- Enabling mixed mode and encrypted calling in Unified CM — Mixed-mode clusters need a CTL update after a CallManager certificate change.
- Public TLS certificate lifetime reductions and UC impactstub — Public CA policy changes (client-auth EKU removal; shorter lifetimes) drive the public-or-enterprise CA decision.
- Setting up certificates on Cisco Expressway — Expressway-C must trust the new Unified CM and IM and Presence certificates and be rediscovered; the Expressway's own certificates are covered there.
- Troubleshooting phone trust and ITL failures in Unified CM — CallManager certificate changes trigger ITL updates and phone resets.
- Unified CM certificate renewal — Renewal of the same certificates once they are in place.
Referenced by
- Troubleshooting SAML SSO sign-in failures in Unified CMstub — Cluster-wide SSO with the Tomcat certificate depends on a multi-server Tomcat certificate
Sources
- 1As of 2026-10-02 the Unified CM Version 15 support page lists 15SU4a (17 March 2026) as its newest release notes and does not list 15SU5, so the FN74345 fixed release does not appear to be available yet.inferredCisco Unified Communications Manager Version 15 · Release Notes list · Checked 2026-10-02
- 2After certificates are regenerated, a system backup must be taken so that the backup contains the new certificates.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Regeneration > note on backup · Checked 2026-10-02
- 3Replacing the CallManager certificate affects phone registration and call processing, so Cisco says to schedule a maintenance window for it.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CallManager certificate (caution) · Checked 2026-10-02
- 4Up to Release 15SU4, the Unified CM CallManager CSR requests the Extended Key Usages Server Authentication, Client Authentication and IP security end system.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 3 (applicable only until Release 15SU4), CallManager row · Checked 2026-10-02
- 5The Release 15 security guide lists Cisco CallManager and Cisco HAProxy as the services to restart after the CallManager certificate changes, plus a CTL update when the cluster is in secure mode.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > services to restart per certificate type (CallManager) · Checked 2026-10-02
- 6Cisco's regeneration tech note lists Cisco CallManager, Cisco CTIManager, Cisco Trust Verification Service and Cisco TFTP as the services to restart after the CallManager certificate changes, plus Cisco HAProxy where SSO or OAuth is configured.Regenerate Certificates In Unified Communications Manager · CallManager certificate > services to restart · Checked 2026-10-02
- 7Expiry notifications are configured at Security > Certificate Monitor in OS Administration, with notification start (days before expiry), frequency, and e-mail recipients.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Certificate Monitoring · Checked 2026-10-02
- 8Certificate expiry monitoring needs the Cisco Certificate Expiry Monitor network service to be running; by default it checks once every 24 hours, and every hour once a certificate has expired or expires within a day.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Monitoring · Checked 2026-10-02
- 9After generating a multi-server CSR, the administrator should check that every node listed in the CSR also appears in the Successful CSR exported list.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Generate CSR (verification of exported list) · Checked 2026-10-02
- 11Cisco warns that the Data Encipherment key usage bit must not be changed or removed when the CA signs the certificate.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > note · Checked 2026-10-02
- 12Deleting a tomcat-trust, CallManager-trust, CAPF-trust or Phone-SAST-trust certificate removes it from every server in the cluster.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Delete Trust Certificate · Checked 2026-10-02
- 13The Distribution field of the Generate CSR window chooses between a certificate for one individual server and a multi-server (SAN) certificate.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > field descriptions (Distribution) · Checked 2026-10-02
- 14The CA chain that signed the Expressway-C certificate must be uploaded to Unified CM as both tomcat-trust and CallManager-trust, even when Unified CM is in non-secure mode.Understand Mobile and Remote Access Certificate Requirements and Apache Traffic Server History · Certificate requirements > Unified CM trust of Expressway-C CA · Checked 2026-10-02
- 15Expressway-C checks the Unified CM tomcat certificate for TLS verify and the CallManager certificate for secure SIP device registrations, so both matter for MRA.Configure and Troubleshoot Collaboration Edge (MRA) Certificates · CUCM certificates / TLS Verify and Secure Registrations · Checked 2026-10-02
- 16After changes on Unified CM or IM and Presence, Expressway-C is resynchronised by going to Configuration > Unified Communications and rediscovering all Unified CM and IM and Presence nodes.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · Ensure that Cisco Expressway-C is Synchronized to Unified CM · Checked 2026-10-02
- 17Changes to the Expressway's own server certificate or its trusted CA certificates take effect only after the Expressway is restarted.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · Cisco Expressway Certificate and TLS Connectivity Issues · Checked 2026-10-02
- 18From Expressway X14.0.8, when these certificate requirements are not met the TLS handshake fails, which can cause loss of redundancy, failover problems or complete login failures.Understand Mobile and Remote Access Certificate Requirements and Apache Traffic Server History · Failure scenarios · Checked 2026-10-02
- 19The name used to define a Unified CM node in Expressway-C (FQDN preferred) must be present as a SAN in that node's Unified CM tomcat certificate.Cisco Expressway Administrator Guide (X15.2) - Unified Communications · Unified Communications > certificate requirements for Unified CM servers · Checked 2026-10-02
- 20For Mobile and Remote Access, Expressway-C must trust the Unified CM and IM and Presence tomcat certificates, which means loading their signing CA certificates into its trusted CA list.Cisco Expressway Administrator Guide (X15.2) - Unified Communications · Unified Communications > Mobile and Remote Access certificate trust · Checked 2026-10-02
- 21FN74345 says the CallManager certificate is used in mutual TLS for SIP trunk connections and internode and intercluster connections, which a server-auth-only certificate breaks.
- 22FN74345 lists Unified CM 14 through 14SU4 and 15 through 15SU4 as affected releases.
- 23FN74345 names Unified CM 15SU5, targeted for Q4 calendar 2026, as the fixed release: it is to separate server and client certificates and add an option to ignore the Client Authentication EKU check on remote peers.
- 24FN74345 lists all releases of the IM and Presence Service as affected.
- 25Cisco Field Notice FN74345 states that public CAs stop issuing certificates with the Client Authentication EKU from May 2026, because the Chrome Root Program limits public roots to Server Authentication.
- 26FN74345 lists XMPP federation over the cup-xmpp-s2s certificate as an affected mutual TLS interface.
- 27FN74345 says the tomcat certificate is used in mutual TLS towards external servers such as LDAP, filebeat and logslash, and for SIP OAuth over MRA.
- 28Another FN74345 workaround is to buy combined-EKU certificates from a public CA that still issues them from roots outside the Chrome Root Store.Field Notice FN74345 - Cisco On-Premises Calling Products: Impact on Secure Communication Due to Upcoming Changes to TLS certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 · Workaround/Solution > alternative public CA option · Checked 2026-10-02
- 29One FN74345 workaround is to move to a private PKI whose CA issues single certificates that carry both the server and client authentication EKUs.Field Notice FN74345 - Cisco On-Premises Calling Products: Impact on Secure Communication Due to Upcoming Changes to TLS certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 · Workaround/Solution > private PKI option · Checked 2026-10-02
- 30For group chat over TLS, the XMPP certificate must carry a wildcard SAN such as *.example.com rather than example.com, which needs the Enable Wildcards in XMPP Federation Security Certificates setting and regenerated certificates.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > wildcard XMPP certificates for group chat · Checked 2026-10-02
- 31On IM and Presence, a multi-server certificate and its signing chain are distributed automatically to all cluster nodes once uploaded to any one node.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > Multi-server certificates · Checked 2026-10-02
- 32On IM and Presence, the CA chain for tomcat certificates goes into tomcat-trust and the CA chain for cup-xmpp and cup-xmpp-s2s certificates goes into cup-xmpp-trust.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > certificate types and trust stores · Checked 2026-10-02
- 33Cisco recommends CA-signed server certificates for Jabber deployments because users are not prompted to accept them.Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Certificate signing options · Checked 2026-10-02
- 34With multiserver SAN certificates, a certificate only needs uploading once per cluster for tomcat and once per cluster for XMPP.Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Multiserver SAN · Checked 2026-10-02
- 35Cisco Jabber validates the tomcat and CallManager certificates of Unified CM and the tomcat and XMPP certificates of IM and Presence.Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Required certificates for on-premises servers · Checked 2026-10-02
- 36When a server certificate is not trusted by the device, Jabber prompts the user to accept or decline it, and declining makes the connection fail.Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Certificate validation · Checked 2026-10-02
- 37A Unified CM CSR can use an RSA key of 1024, 2048, 3072 or 4096 bits or an EC key of 256 or 384 bits, and the hash algorithm should be at least as strong as the key length.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > field descriptions (Key Type, Key Length, Hash Algorithm) · Checked 2026-10-02
- 38If the cluster is in mixed mode, the CTL file must be updated when the CallManager certificate changes.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > CallManager certificate note (mixed mode) · Checked 2026-10-02
- 39A Multi-Server SAN CSR for the CallManager certificate lists only the Unified CM nodes, not the IM and Presence nodes.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CallManager certificate CSR · Checked 2026-10-02
- 40When Multi-Server SAN is chosen as the Distribution for a tomcat CSR, the SAN list is auto-populated with all Unified CM and IM and Presence nodes of the cluster, together with a parent domain.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Generate CSR (Multi-Server SAN distribution, tomcat) · Checked 2026-10-02
- 41Multi-Server SAN CSRs for the cup-xmpp and cup-xmpp-s2s certificates list only the IM and Presence nodes.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CUP-XMPP and CUP-XMPP-S2S certificate CSR · Checked 2026-10-02
- 42Only one CSR per server and certificate type can exist, so generating a new CSR replaces the old one and a certificate signed from the old CSR can no longer be installed.Create New Certificates from Signed CA Certificates · Background / CSR handling · Checked 2026-10-02
- 43Cisco warns not to regenerate the CallManager and TVS certificates at the same time, because doing so can cause an unrecoverable mismatch with the ITL installed on endpoints.Regenerate Certificates In Unified Communications Manager · CallManager certificate > caution · Checked 2026-10-02
- 44Certificates should be replaced one type at a time, with phone registration checked in RTMT before moving on to the next certificate type.Regenerate Certificates In Unified Communications Manager · Regeneration process > order · Checked 2026-10-02
- 45Because automatic distribution is described only for multi-server certificates, a single-server (per-node) certificate has to be requested, signed, uploaded and activated separately on each node.inferredSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note; Generate a Certificate Signing Request > Distribution · Checked 2026-10-02
- 46Phones reset automatically to fetch an updated ITL file after the CallManager, CAPF or TVS certificate is regenerated or renewed.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > ITL file / phone reset note · Checked 2026-10-02
- 47Public CAs generally require an FQDN rather than an IP address as the server identity, and some sign only one certificate per FQDN.Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Public CA requirements · Checked 2026-10-02
- 48Every time a node is added to the cluster or rebuilt, a new multi-server certificate must be generated and uploaded to the cluster.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note · Checked 2026-10-02
- 49Regenerate in Certificate Management overwrites the existing certificate with a new self-signed one, and the services tied to that certificate must then be restarted.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Regenerate a Certificate · Checked 2026-10-02
- 50Before reusing a CA-signed multi-SAN tomcat certificate for CallManager, the tomcat certificate's CA chain must be uploaded to the CallManager-trust store.Implement Reuse of Multi-SAN Tomcat Certificate for CallManager · Configure > upload CA chain to CallManager-trust · Checked 2026-10-02
- 51After the reuse, Cisco HAProxy is restarted on all nodes with utils service restart Cisco HAProxy; in a mixed-mode cluster utils ctl update CTLFile is run on the publisher and phones are reset to receive the new CTL.Implement Reuse of Multi-SAN Tomcat Certificate for CallManager · Configure > restart services and update CTL · Checked 2026-10-02
- 53A multi-server SAN tomcat certificate can be reused as the CallManager certificate from Security > Certificate Management > Reuse Certificate; the tomcat certificate must be multi-server SAN for this to work.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Reuse Tomcat Certificate for CallManager · Checked 2026-10-02
- 54The CLI command show cert list own confirms that CallManager is reusing the tomcat certificate.Implement Reuse of Multi-SAN Tomcat Certificate for CallManager · Verify · Checked 2026-10-02
- 55The root certificate of the signing CA, and any intermediate, must be installed in the trust store before the CA-signed certificate itself is uploaded.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Upload Certificate or Certificate Chain · Checked 2026-10-02
- 56Some phone models may fail to register if the RSA key length chosen for the CallManager certificate is greater than 2048 bits; supported phones are listed in Cisco Unified Reporting.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > Key Length note · Checked 2026-10-02
- 57After a cup-xmpp-s2s certificate is uploaded, the Cisco XCP XMPP Federation Connection Manager service must be restarted.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > post-upload service restarts (cup-xmpp-s2s) · Checked 2026-10-02
- 58The SANs in the CA-signed certificate must match those in the CSR; order does not matter, but the CA may not add or remove entries, or the upload fails.Create New Certificates from Signed CA Certificates · Background / SAN requirements · Checked 2026-10-02
- 59Cisco's multi-server SAN procedure says to verify that SSO is disabled before uploading a tomcat certificate.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Upload certificate (caution) · Checked 2026-10-02
- 60Cisco says the TFTP service should be restarted when a tomcat certificate is uploaded.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Upload Certificate or Certificate Chain (note) · Checked 2026-10-02
- 61Up to Release 15SU4, the Unified CM tomcat CSR requests the Extended Key Usages Server Authentication and Client Authentication.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 3 (applicable only until Release 15SU4), tomcat row · Checked 2026-10-02
- 62After a new tomcat certificate is installed, the Cisco Tomcat service is restarted on every node with the CLI command utils service restart Cisco Tomcat, starting with the publisher and then the subscribers.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Restart Tomcat service · Checked 2026-10-02
- 63When the CA-signed multi-server tomcat certificate is uploaded with purpose tomcat, the confirmation message lists the cluster nodes it was applied to, which should be all of them.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Upload the signed certificate · Checked 2026-10-02
- 64The upload order is the root CA certificate as <type>-trust, then any intermediate as <type>-trust, then the signed leaf as <type>, for example tomcat-trust then tomcat.Create New Certificates from Signed CA Certificates · Configure > Upload certificates · Checked 2026-10-02
- 65In Unified CM, a multi-server (SAN) CA-signed certificate applies to the cluster nodes only when it is uploaded to the publisher.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note · Checked 2026-10-02
- 66Opening https://<node FQDN>:8443/ccmadmin in a browser and inspecting the presented certificate confirms that the new tomcat certificate is active.Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Verify · Checked 2026-10-02
- 67The Unified CM Release 15 security guide's IM and Presence CSR key usage table marks cup-xmpp, cup-xmpp-ECDSA, cup-xmpp-s2s and cup-xmpp-s2s-ECDSA as not multi-server.disputedSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 4 IM and Presence Service CSR Key Usage Extensions (applicable only until 15SU4), Multi-server column · Checked 2026-10-02
- 68The IM and Presence Release 15 configuration guide lists cup-xmpp, cup-xmpp-ECDSA, cup-xmpp-s2s and cup-xmpp-s2s-ECDSA as supporting multi-server certificates.disputedConfiguration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > Multi-server certificates (supported certificate types) · Checked 2026-10-02
- 69After a cup-xmpp or cup-xmpp-ECDSA certificate is uploaded, the Cisco XCP Router service must be restarted on all IM and Presence nodes.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > post-upload service restarts (cup-xmpp) · Checked 2026-10-02
Documents
tier 2 current vendor documentation
Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.2) - Unified Communications
tier 2 current vendor documentation
Cisco Unified Communications Manager Version 15
tier 2 current vendor documentation
Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates
tier 2 current vendor documentation
Configure and Troubleshoot Collaboration Edge (MRA) Certificates
tier 2 current vendor documentation
Create New Certificates from Signed CA Certificates
tier 2 current vendor documentation
Field Notice FN74345 - Cisco On-Premises Calling Products: Impact on Secure Communication Due to Upcoming Changes to TLS certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026
tier 2 current vendor documentation
Implement Reuse of Multi-SAN Tomcat Certificate for CallManager
tier 2 current vendor documentation
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting
tier 2 current vendor documentation
Planning Guide for Cisco Jabber 14.1 - Security and certificates
tier 2 current vendor documentation
Regenerate Certificates In Unified Communications Manager
tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates
tier 2 current vendor documentation
Setup Unified Communication Cluster (CA-signed multi-server SAN certificates)
tier 2 current vendor documentation
Understand Mobile and Remote Access Certificate Requirements and Apache Traffic Server History
Cite this page
APA
WarmTransfer. (2026, October 2). Setting up multi-server SAN certificates in Unified CM and IM and Presence. WarmTransfer. https://warmtransfer.net/guides/cucm-multi-server-certificate-setup
BibTeX
@misc{warmtransfer-cucm-multi-server-certificate-setup,
title = {Setting up multi-server SAN certificates in Unified CM and IM and Presence},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cucm-multi-server-certificate-setup},
note = {Verified 2026-10-02}
}