Source note · Local Gateway design and configuration
A TLS handshake failure after a Local Gateway certificate renewal may be a third-party session border controller enforcing strict extended key usage validation and rejecting a certificate without Client Authentication extended key usage, and Cisco states that any such requirement is determined by the session border controller vendor rather than by Webex Calling.
Checked 2026-09-15
Any requirement for Client Authentication EKU is determined by the SBC vendor, not by Webex Calling. Any TLS failure related to EKU validation is due to SBC-side configuration or default behavior.
- Vendor
- Cisco
- Product
- Webex Calling
- Subsystem
- Local Gateway
- Deployment
- not restricted
- Region
- not restricted
- Release range
- not restricted
- Checked
- 2026-09-15
Sources
- Get started with Local Gateway — Cisco Systems, Inc. (Webex Help Center) · tier 2 current vendor documentation · Troubleshooting TLS Handshake establishment, cause and resolution table plus the closing note
Cite this note
APA
WarmTransfer. (2026, September 15). Local Gateway design and configuration: source note wxlgw-eku-failure-belongs-to-the-sbc. WarmTransfer. https://warmtransfer.net/knowledge/claims/wxlgw-eku-failure-belongs-to-the-sbc
BibTeX
@misc{warmtransfer-claim-wxlgw-eku-failure-belongs-to-the-sbc,
title = {Local Gateway design and configuration: source note wxlgw-eku-failure-belongs-to-the-sbc},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/wxlgw-eku-failure-belongs-to-the-sbc},
note = {Source note wxlgw-eku-failure-belongs-to-the-sbc, checked 2026-09-15}
}