Source record · tier 2 current vendor documentation
Security requirements for Webex Calling
- Publisher
- Cisco Systems, Inc. (help.webex.com)
- URL
- https://help.webex.com/en-us/article/jwkbt2/Security-requirements-for-Webex-Calling
- Published
- 2026-04-28
- Updated
- unknown
- Accessed
- 2026-09-16
- HTTP status
- 200
- License
- Cisco proprietary documentation, all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Cisco states that a certificate can be shared with more than one Local Gateway provided the fully qualified domain name requirements are satisfied. in context
- Cisco requires that a signed Local Gateway certificate always has a valid expiry and that the root or intermediate certificates used to sign it also have a valid expiry and are not revoked, and separately requires the Webex trust bundle to be uploaded onto the Cisco Unified Border Element. in context
- The Webex Calling security requirements article dated 28 April 2026 states that a trunk configured with an SRV address must contain that SRV name in the certificate common name or subject alternative name and that the records the SRV address resolves to, meaning the CNAME the A record or the IP address, are optional in the subject alternative name. disputed in context
- A Webex Calling endpoint must use the _sips._tcp service and protocol combination as the prefix for the DNS SRV lookup that obtains the host address for TLS-based communication, must honour the host port weight and priority advertised for each host address, and must create an affinity of host to port when opening the socket for SIP registration, with selection by priority and weight following RFC 2782. in context
- For Webex Calling mutual TLS, the peer certificate must be signed by a CA on Webex's approved list, be within its validity period, chain through unexpired and unrevoked roots and intermediates, and carry the Control Hub FQDN in its CN or SAN. in context
- Webex Calling secure SIP uses port 5061, discovered through a _sips._tcp DNS SRV lookup. in context
- Webex Calling accepts peer certificates that carry only the Server Authentication EKU; the Client Authentication EKU is not required. in context
- Webex Calling supports TLS 1.2 and TLS 1.3 for secure SIP. in context
- The Webex Calling security requirements article carries an Out of scope section naming the network security material it does not cover, including F5 requirements for certificate authorities and ciphers. in context
- Cisco lists 14 TLS cipher suites supported for secure SIP in Webex Calling, of which TLS_AES_256_GCM_SHA384 is the only one at 256 bits and the remaining 13 are AES-128 suites spanning the TLS 1.3 AES_128_GCM form and the ECDHE ECDH and DHE key exchanges in GCM and CBC modes. in context
- The Webex Calling security requirements article describes endpoint discovery, TLS versions and ciphers, SRTP keys and mutual TLS certificates across 6889 characters and mentions OAuth 0 times, so the corpus holds no Webex Calling source describing SIP OAuth as an endpoint or trunk authentication method. field report in context
- Cisco gives AES_CM_128_HMAC_SHA1_80 as the only SRTP key supported for secure media in Webex Calling. in context
- Cisco states that the TLS versions supported for secure SIP in Webex Calling are TLS 1.2 and TLS 1.3. in context
- Cisco's Webex Calling security requirements list AES_CM_128_HMAC_SHA1_80 as the only supported SRTP key cipher suite. in context
- Webex Calling supports TLS 1.2 and TLS 1.3 for secure SIP. in context
Cite this source record
APA
WarmTransfer. (2026, April 28). Security requirements for Webex Calling. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-jwkbt2-security-requirements
BibTeX
@misc{warmtransfer-cisco-help-jwkbt2-security-requirements,
title = {Security requirements for Webex Calling},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-jwkbt2-security-requirements},
note = {Cisco Systems, Inc. (help.webex.com), accessed 2026-09-16}
}