Source record · tier 2 current vendor documentation
Cisco Expressway Certificate Creation and Use Deployment Guide (X15.5) - Loading Certificates and Keys Onto Expressway
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-5/cert-creation-use/exwy_b_cisco-expressway-certificate-creation-and-use-deployment-guide-x155/exwy_m_loading-certificates-and-keys-onto.html
- Published
- 2026-07-29
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- Cisco documentation; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- When changing a server certificate, the new trusted CA certificate is added on all nodes of the cluster before the new server certificate is applied to every node. in context
- Before changing an existing server certificate in a cluster whose TLS Verification mode (System > Clustering) is Enforce, change it to Permissive. in context
- After the certificate change, TLS Verification mode is set back to Enforce if it was changed, and CA certificates no longer in use are removed. in context
- After a server certificate change, the cluster nodes are restarted one at a time, letting each recover before restarting the next. in context
- The Expressway trust store supports at most 1000 uploaded certificate authorities. in context
- When a TLS connection requires certificate verification, the presented certificate must be signed by a CA in the Expressway trusted list with a full chain of trust. in context
- CA certificates are added in PEM format at Maintenance > Security > Trusted CA certificate using Append CA certificate, which keeps the existing list. in context
- Reset to default CA certificate replaces every uploaded CA certificate with the system's original trusted CA list. in context
- Cisco recommends installing the CA certificate before installing the server certificate on Expressway. in context
- If the CSR was generated outside Expressway, the matching unencrypted private key PEM file must be uploaded along with the server certificate. in context
Cite this source record
APA
WarmTransfer. (2026, July 29). Cisco Expressway Certificate Creation and Use Deployment Guide (X15.5) - Loading Certificates and Keys Onto Expressway. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-exwy-x155-cert-loading
BibTeX
@misc{warmtransfer-cisco-exwy-x155-cert-loading,
title = {Cisco Expressway Certificate Creation and Use Deployment Guide (X15.5) - Loading Certificates and Keys Onto Expressway},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-exwy-x155-cert-loading},
note = {Cisco Systems, accessed 2026-09-30}
}