Cisco's Preferred Architecture warns that a CA-signed Tomcat certificate used for ILS must carry the TLS Web Client Authentication extended key usage, because the initiating side also uses it as a client certificate.
Checked 2026-10-01
- Vendor
- Cisco
- Product
- Cisco Unified Communications Manager
- Subsystem
- Certificates
- Deployment
- on-premises
- Region
- not restricted
- Release range
- 12.x design guidance
- Checked
- 2026-10-01
Sources
- Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control — Cisco Systems · tier 2 current vendor documentation · Call Control > certificate guidance for Tomcat (ILS and UDS)
Cite this note
APA
WarmTransfer. (2026, October 1). Setting up ILS and Global Dial Plan Replication in Unified CM: source note cucm-ils-gdpr-setup-tomcat-client-eku. WarmTransfer. https://warmtransfer.net/knowledge/claims/cucm-ils-gdpr-setup-tomcat-client-eku
BibTeX
@misc{warmtransfer-claim-cucm-ils-gdpr-setup-tomcat-client-eku,
title = {Setting up ILS and Global Dial Plan Replication in Unified CM: source note cucm-ils-gdpr-setup-tomcat-client-eku},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/cucm-ils-gdpr-setup-tomcat-client-eku},
note = {Source note cucm-ils-gdpr-setup-tomcat-client-eku, checked 2026-10-01}
}