Guide · in research

Setting up multi-server SAN certificates in Unified CM and IM and Presence

Verified 2026-10-02 · 69 sources · tier 2

In research. This guide has not been written yet. It has 69 sources to build on.

See also

Configures

  • Cisco unified cm — Certificate management in Cisco Unified OS Administration on Unified CM and IM and Presence nodes.

Related to

Referenced by

Sources

  1. 1
    As of 2026-10-02 the Unified CM Version 15 support page lists 15SU4a (17 March 2026) as its newest release notes and does not list 15SU5, so the FN74345 fixed release does not appear to be available yet.inferred
    Cisco Unified Communications Manager Version 15 · Release Notes list · Checked 2026-10-02
  2. 2
    After certificates are regenerated, a system backup must be taken so that the backup contains the new certificates.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Regeneration > note on backup · Checked 2026-10-02
  3. 3
    Replacing the CallManager certificate affects phone registration and call processing, so Cisco says to schedule a maintenance window for it.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CallManager certificate (caution) · Checked 2026-10-02
  4. 4
    Up to Release 15SU4, the Unified CM CallManager CSR requests the Extended Key Usages Server Authentication, Client Authentication and IP security end system.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 3 (applicable only until Release 15SU4), CallManager row · Checked 2026-10-02
  5. 5
    The Release 15 security guide lists Cisco CallManager and Cisco HAProxy as the services to restart after the CallManager certificate changes, plus a CTL update when the cluster is in secure mode.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > services to restart per certificate type (CallManager) · Checked 2026-10-02
  6. 6
    Cisco's regeneration tech note lists Cisco CallManager, Cisco CTIManager, Cisco Trust Verification Service and Cisco TFTP as the services to restart after the CallManager certificate changes, plus Cisco HAProxy where SSO or OAuth is configured.
    Regenerate Certificates In Unified Communications Manager · CallManager certificate > services to restart · Checked 2026-10-02
  7. 7
    Expiry notifications are configured at Security > Certificate Monitor in OS Administration, with notification start (days before expiry), frequency, and e-mail recipients.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Certificate Monitoring · Checked 2026-10-02
  8. 8
    Certificate expiry monitoring needs the Cisco Certificate Expiry Monitor network service to be running; by default it checks once every 24 hours, and every hour once a certificate has expired or expires within a day.
  9. 9
    After generating a multi-server CSR, the administrator should check that every node listed in the CSR also appears in the Successful CSR exported list.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Generate CSR (verification of exported list) · Checked 2026-10-02
  10. 10
    A certificate signing request for Unified CM is generated in Cisco Unified OS Administration at Security > Certificate Management > Generate CSR; for a multi-server certificate this is done on the publisher.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Generate CSR (step 1) · Checked 2026-10-02
  11. 11
    Cisco warns that the Data Encipherment key usage bit must not be changed or removed when the CA signs the certificate.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > note · Checked 2026-10-02
  12. 12
    Deleting a tomcat-trust, CallManager-trust, CAPF-trust or Phone-SAST-trust certificate removes it from every server in the cluster.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Delete Trust Certificate · Checked 2026-10-02
  13. 13
    The Distribution field of the Generate CSR window chooses between a certificate for one individual server and a multi-server (SAN) certificate.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > field descriptions (Distribution) · Checked 2026-10-02
  14. 14
    The CA chain that signed the Expressway-C certificate must be uploaded to Unified CM as both tomcat-trust and CallManager-trust, even when Unified CM is in non-secure mode.
    Understand Mobile and Remote Access Certificate Requirements and Apache Traffic Server History · Certificate requirements > Unified CM trust of Expressway-C CA · Checked 2026-10-02
  15. 15
    Expressway-C checks the Unified CM tomcat certificate for TLS verify and the CallManager certificate for secure SIP device registrations, so both matter for MRA.
    Configure and Troubleshoot Collaboration Edge (MRA) Certificates · CUCM certificates / TLS Verify and Secure Registrations · Checked 2026-10-02
  16. 16
    After changes on Unified CM or IM and Presence, Expressway-C is resynchronised by going to Configuration > Unified Communications and rediscovering all Unified CM and IM and Presence nodes.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · Ensure that Cisco Expressway-C is Synchronized to Unified CM · Checked 2026-10-02
  17. 17
    Changes to the Expressway's own server certificate or its trusted CA certificates take effect only after the Expressway is restarted.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · Cisco Expressway Certificate and TLS Connectivity Issues · Checked 2026-10-02
  18. 18
    From Expressway X14.0.8, when these certificate requirements are not met the TLS handshake fails, which can cause loss of redundancy, failover problems or complete login failures.
  19. 19
    The name used to define a Unified CM node in Expressway-C (FQDN preferred) must be present as a SAN in that node's Unified CM tomcat certificate.
    Cisco Expressway Administrator Guide (X15.2) - Unified Communications · Unified Communications > certificate requirements for Unified CM servers · Checked 2026-10-02
  20. 20
    For Mobile and Remote Access, Expressway-C must trust the Unified CM and IM and Presence tomcat certificates, which means loading their signing CA certificates into its trusted CA list.
    Cisco Expressway Administrator Guide (X15.2) - Unified Communications · Unified Communications > Mobile and Remote Access certificate trust · Checked 2026-10-02
  21. 21
    FN74345 says the CallManager certificate is used in mutual TLS for SIP trunk connections and internode and intercluster connections, which a server-auth-only certificate breaks.
  22. 22
  23. 23
    FN74345 names Unified CM 15SU5, targeted for Q4 calendar 2026, as the fixed release: it is to separate server and client certificates and add an option to ignore the Client Authentication EKU check on remote peers.
  24. 24
  25. 25
    Cisco Field Notice FN74345 states that public CAs stop issuing certificates with the Client Authentication EKU from May 2026, because the Chrome Root Program limits public roots to Server Authentication.
  26. 26
    FN74345 lists XMPP federation over the cup-xmpp-s2s certificate as an affected mutual TLS interface.
  27. 27
    FN74345 says the tomcat certificate is used in mutual TLS towards external servers such as LDAP, filebeat and logslash, and for SIP OAuth over MRA.
  28. 28
    Another FN74345 workaround is to buy combined-EKU certificates from a public CA that still issues them from roots outside the Chrome Root Store.
  29. 29
    One FN74345 workaround is to move to a private PKI whose CA issues single certificates that carry both the server and client authentication EKUs.
  30. 30
    For group chat over TLS, the XMPP certificate must carry a wildcard SAN such as *.example.com rather than example.com, which needs the Enable Wildcards in XMPP Federation Security Certificates setting and regenerated certificates.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > wildcard XMPP certificates for group chat · Checked 2026-10-02
  31. 31
    On IM and Presence, a multi-server certificate and its signing chain are distributed automatically to all cluster nodes once uploaded to any one node.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > Multi-server certificates · Checked 2026-10-02
  32. 32
    On IM and Presence, the CA chain for tomcat certificates goes into tomcat-trust and the CA chain for cup-xmpp and cup-xmpp-s2s certificates goes into cup-xmpp-trust.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > certificate types and trust stores · Checked 2026-10-02
  33. 33
    Cisco recommends CA-signed server certificates for Jabber deployments because users are not prompted to accept them.
    Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Certificate signing options · Checked 2026-10-02
  34. 34
    With multiserver SAN certificates, a certificate only needs uploading once per cluster for tomcat and once per cluster for XMPP.
    Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Multiserver SAN · Checked 2026-10-02
  35. 35
    Cisco Jabber validates the tomcat and CallManager certificates of Unified CM and the tomcat and XMPP certificates of IM and Presence.
    Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Required certificates for on-premises servers · Checked 2026-10-02
  36. 36
    When a server certificate is not trusted by the device, Jabber prompts the user to accept or decline it, and declining makes the connection fail.
    Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Certificate validation · Checked 2026-10-02
  37. 37
    A Unified CM CSR can use an RSA key of 1024, 2048, 3072 or 4096 bits or an EC key of 256 or 384 bits, and the hash algorithm should be at least as strong as the key length.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > field descriptions (Key Type, Key Length, Hash Algorithm) · Checked 2026-10-02
  38. 38
    If the cluster is in mixed mode, the CTL file must be updated when the CallManager certificate changes.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > CallManager certificate note (mixed mode) · Checked 2026-10-02
  39. 39
    A Multi-Server SAN CSR for the CallManager certificate lists only the Unified CM nodes, not the IM and Presence nodes.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CallManager certificate CSR · Checked 2026-10-02
  40. 40
    When Multi-Server SAN is chosen as the Distribution for a tomcat CSR, the SAN list is auto-populated with all Unified CM and IM and Presence nodes of the cluster, together with a parent domain.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Generate CSR (Multi-Server SAN distribution, tomcat) · Checked 2026-10-02
  41. 41
    Multi-Server SAN CSRs for the cup-xmpp and cup-xmpp-s2s certificates list only the IM and Presence nodes.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > CUP-XMPP and CUP-XMPP-S2S certificate CSR · Checked 2026-10-02
  42. 42
    Only one CSR per server and certificate type can exist, so generating a new CSR replaces the old one and a certificate signed from the old CSR can no longer be installed.
    Create New Certificates from Signed CA Certificates · Background / CSR handling · Checked 2026-10-02
  43. 43
    Cisco warns not to regenerate the CallManager and TVS certificates at the same time, because doing so can cause an unrecoverable mismatch with the ITL installed on endpoints.
    Regenerate Certificates In Unified Communications Manager · CallManager certificate > caution · Checked 2026-10-02
  44. 44
    Certificates should be replaced one type at a time, with phone registration checked in RTMT before moving on to the next certificate type.
    Regenerate Certificates In Unified Communications Manager · Regeneration process > order · Checked 2026-10-02
  45. 45
    Because automatic distribution is described only for multi-server certificates, a single-server (per-node) certificate has to be requested, signed, uploaded and activated separately on each node.inferred
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note; Generate a Certificate Signing Request > Distribution · Checked 2026-10-02
  46. 46
    Phones reset automatically to fetch an updated ITL file after the CallManager, CAPF or TVS certificate is regenerated or renewed.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > ITL file / phone reset note · Checked 2026-10-02
  47. 47
    Public CAs generally require an FQDN rather than an IP address as the server identity, and some sign only one certificate per FQDN.
    Planning Guide for Cisco Jabber 14.1 - Security and certificates · Security and certificates > Public CA requirements · Checked 2026-10-02
  48. 48
    Every time a node is added to the cluster or rebuilt, a new multi-server certificate must be generated and uploaded to the cluster.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note · Checked 2026-10-02
  49. 49
    Regenerate in Certificate Management overwrites the existing certificate with a new self-signed one, and the services tied to that certificate must then be restarted.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Regenerate a Certificate · Checked 2026-10-02
  50. 50
    Before reusing a CA-signed multi-SAN tomcat certificate for CallManager, the tomcat certificate's CA chain must be uploaded to the CallManager-trust store.
    Implement Reuse of Multi-SAN Tomcat Certificate for CallManager · Configure > upload CA chain to CallManager-trust · Checked 2026-10-02
  51. 51
    After the reuse, Cisco HAProxy is restarted on all nodes with utils service restart Cisco HAProxy; in a mixed-mode cluster utils ctl update CTLFile is run on the publisher and phones are reset to receive the new CTL.
    Implement Reuse of Multi-SAN Tomcat Certificate for CallManager · Configure > restart services and update CTL · Checked 2026-10-02
  52. 52
    When the tomcat certificate is reused for CallManager, the CallManager certificate is no longer shown in the Certificate Management GUI.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Reuse Tomcat Certificate for CallManager > note · Checked 2026-10-02
  53. 53
    A multi-server SAN tomcat certificate can be reused as the CallManager certificate from Security > Certificate Management > Reuse Certificate; the tomcat certificate must be multi-server SAN for this to work.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Reuse Tomcat Certificate for CallManager · Checked 2026-10-02
  54. 54
    The CLI command show cert list own confirms that CallManager is reusing the tomcat certificate.
  55. 55
    The root certificate of the signing CA, and any intermediate, must be installed in the trust store before the CA-signed certificate itself is uploaded.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Upload Certificate or Certificate Chain · Checked 2026-10-02
  56. 56
    Some phone models may fail to register if the RSA key length chosen for the CallManager certificate is greater than 2048 bits; supported phones are listed in Cisco Unified Reporting.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Generate a Certificate Signing Request > Key Length note · Checked 2026-10-02
  57. 57
    After a cup-xmpp-s2s certificate is uploaded, the Cisco XCP XMPP Federation Connection Manager service must be restarted.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > post-upload service restarts (cup-xmpp-s2s) · Checked 2026-10-02
  58. 58
    The SANs in the CA-signed certificate must match those in the CSR; order does not matter, but the CA may not add or remove entries, or the upload fails.
    Create New Certificates from Signed CA Certificates · Background / SAN requirements · Checked 2026-10-02
  59. 59
    Cisco's multi-server SAN procedure says to verify that SSO is disabled before uploading a tomcat certificate.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Upload certificate (caution) · Checked 2026-10-02
  60. 60
    Cisco says the TFTP service should be restarted when a tomcat certificate is uploaded.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Manage Certificates > Upload Certificate or Certificate Chain (note) · Checked 2026-10-02
  61. 61
    Up to Release 15SU4, the Unified CM tomcat CSR requests the Extended Key Usages Server Authentication and Client Authentication.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 3 (applicable only until Release 15SU4), tomcat row · Checked 2026-10-02
  62. 62
    After a new tomcat certificate is installed, the Cisco Tomcat service is restarted on every node with the CLI command utils service restart Cisco Tomcat, starting with the publisher and then the subscribers.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Restart Tomcat service · Checked 2026-10-02
  63. 63
    When the CA-signed multi-server tomcat certificate is uploaded with purpose tomcat, the confirmation message lists the cluster nodes it was applied to, which should be all of them.
    Setup Unified Communication Cluster (CA-signed multi-server SAN certificates) · Configure > Upload the signed certificate · Checked 2026-10-02
  64. 64
    The upload order is the root CA certificate as <type>-trust, then any intermediate as <type>-trust, then the signed leaf as <type>, for example tomcat-trust then tomcat.
    Create New Certificates from Signed CA Certificates · Configure > Upload certificates · Checked 2026-10-02
  65. 65
    In Unified CM, a multi-server (SAN) CA-signed certificate applies to the cluster nodes only when it is uploaded to the publisher.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Multi-server (SAN) certificates note · Checked 2026-10-02
  66. 66
    Opening https://<node FQDN>:8443/ccmadmin in a browser and inspecting the presented certificate confirms that the new tomcat certificate is active.
  67. 67
    The Unified CM Release 15 security guide's IM and Presence CSR key usage table marks cup-xmpp, cup-xmpp-ECDSA, cup-xmpp-s2s and cup-xmpp-s2s-ECDSA as not multi-server.disputed
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificate Signing Request Key Usage Extensions > Table 4 IM and Presence Service CSR Key Usage Extensions (applicable only until 15SU4), Multi-server column · Checked 2026-10-02
  68. 68
    The IM and Presence Release 15 configuration guide lists cup-xmpp, cup-xmpp-ECDSA, cup-xmpp-s2s and cup-xmpp-s2s-ECDSA as supporting multi-server certificates.disputed
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > Multi-server certificates (supported certificate types) · Checked 2026-10-02
  69. 69
    After a cup-xmpp or cup-xmpp-ECDSA certificate is uploaded, the Cisco XCP Router service must be restarted on all IM and Presence nodes.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates · Configure Certificates > post-upload service restarts (cup-xmpp) · Checked 2026-10-02

Documents

tier 2 current vendor documentation

Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates

Cisco Systems · 2026-08-31 · accessed 2026-09-25

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.2) - Unified Communications

Cisco Systems · 2025-02-07 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Unified Communications Manager Version 15

Cisco Systems, Inc. · accessed 2026-09-04

tier 2 current vendor documentation

Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Certificates

Cisco Systems · 2026-01-07 · accessed 2026-10-02

tier 2 current vendor documentation

Configure and Troubleshoot Collaboration Edge (MRA) Certificates

Cisco Systems · 2023-06-22 · accessed 2026-09-24

tier 2 current vendor documentation

Create New Certificates from Signed CA Certificates

Cisco Systems · 2025-11-12 · accessed 2026-09-25

tier 2 current vendor documentation

Implement Reuse of Multi-SAN Tomcat Certificate for CallManager

Cisco Systems · 2024-10-24 · accessed 2026-10-02

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Planning Guide for Cisco Jabber 14.1 - Security and certificates

Cisco Systems · 2024-04-02 · accessed 2026-09-25

tier 2 current vendor documentation

Regenerate Certificates In Unified Communications Manager

Cisco Systems · 2026-07-20 · accessed 2026-09-25

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates

Cisco Systems · 2026-09-22 · accessed 2026-09-25

tier 2 current vendor documentation

Setup Unified Communication Cluster (CA-signed multi-server SAN certificates)

Cisco Systems · 2024-06-21 · accessed 2026-10-02

tier 2 current vendor documentation

Understand Mobile and Remote Access Certificate Requirements and Apache Traffic Server History

Cisco Systems · 2026-01-20 · accessed 2026-10-02

Cite this page

APA

WarmTransfer. (2026, October 2). Setting up multi-server SAN certificates in Unified CM and IM and Presence. WarmTransfer. https://warmtransfer.net/guides/cucm-multi-server-certificate-setup

BibTeX

@misc{warmtransfer-cucm-multi-server-certificate-setup,
  title  = {Setting up multi-server SAN certificates in Unified CM and IM and Presence},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cucm-multi-server-certificate-setup},
  note   = {Verified 2026-10-02}
}