A TLS handshake failure after a Local Gateway certificate renewal may be a third-party session border controller enforcing strict extended key usage validation and rejecting a certificate without Client Authentication extended key usage, and Cisco states that any such requirement is determined by the session border controller vendor rather than by Webex Calling.

Checked 2026-09-15

Any requirement for Client Authentication EKU is determined by the SBC vendor, not by Webex Calling. Any TLS failure related to EKU validation is due to SBC-side configuration or default behavior.
Vendor
Cisco
Product
Webex Calling
Subsystem
Local Gateway
Deployment
not restricted
Region
not restricted
Release range
not restricted
Checked
2026-09-15

Sources

Cite this note

APA

WarmTransfer. (2026, September 15). Local Gateway design and configuration: source note wxlgw-eku-failure-belongs-to-the-sbc. WarmTransfer. https://warmtransfer.net/knowledge/claims/wxlgw-eku-failure-belongs-to-the-sbc

BibTeX

@misc{warmtransfer-claim-wxlgw-eku-failure-belongs-to-the-sbc,
  title  = {Local Gateway design and configuration: source note wxlgw-eku-failure-belongs-to-the-sbc},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/wxlgw-eku-failure-belongs-to-the-sbc},
  note   = {Source note wxlgw-eku-failure-belongs-to-the-sbc, checked 2026-09-15}
}

Read in context