Cisco Unity Connection Minimum TLS Version Support

Slides:



Advertisements
Similar presentations
Dexter Team IPv6 in Connection 8.5.
Advertisements

Chapter 9: Access Control Lists
BASIC CRYPTOGRAPHY CONCEPT. Secure Socket Layer (SSL)  SSL was first used by Netscape.  To ensure security of data sent through HTTP, LDAP or POP3.
© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2014 Cisco and/or its affiliates. All rights reserved. 1 URI Dialing Unity.
Cisco Confidential © 2013 Cisco and/or its affiliates. All rights reserved. 1 Unity Connection Qualification for Prime Collaboration Development Release.
© 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2012 Cisco and/or its affiliates. All rights reserved. 1 SRSV MWI Functionality.
NetAcumen ActiveX Install Instructions. Requirements: Administrator: User must be logged in as Administrator of the machine. If you are not the administrator,
© 2008 Cisco Systems, Inc. All rights reserved. Cisco Unity Connection 7.0 Directory Integration TOI Manoj Agrawal
Cisco Confidential © 2011 Cisco and/or its affiliates. All rights reserved bit RHEL 6 Update 2 OS Upgrade RHEL TEAM
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Backup, Restore, and Server Replacement Josh Rose UCBU Software Engineer.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. 1 SAN Certificate in Unity Connection Presenter Name: Bhawna Goel.
Cisco Discovery Working at a Small-to-Medium Business or ISP CHAPTER 7 ISP Services Jr.
PC Maintenance: Preparing for A+ Certification Chapter 25: The Internet.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
Internet Addresses. Universal Identifiers Universal Communication Service - Communication system which allows any host to communicate with any other host.
Missed Call Notification Unity Connection 11.0
1 © 2002, Cisco Systems, Inc. All rights reserved. Session Number Presentation_ID Key differences between Cisco Unity Connection and Cisco Unity Manjit.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Otomo End User SSO - TOI March 2014 Otomo 10.5 – End User SSO Support.
© 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2012 Cisco and/or its affiliates. All rights reserved. 1 Voice Mailbox.
TOI: FIPS compliance Unity Connection 8.6 Mike Canfield- Test engineer Yolanda Liu – Dev engineer.
© 2015 Cisco System Inc. All rights reserved Cisco Confidential 1 © 2015 Cisco System Inc. All rights reserved. 1 Next Generation Security Support in Unity.
© 2013 Cisco System Inc. All rights reserved Cisco Confidential 1 © 2013 Cisco System Inc. All rights reserved. 1 System Backup And Restore Utility.
Presentation_ID © 2012, Cisco Systems, Inc. All rights reserved. Cisco Confidential.
© 2006 Cisco Systems, Inc. All rights reserved.1 Connection 7.0 Serviceability Reports Todd Blaisdell.
© 2013 Cisco System Inc. All rights reserved Cisco Confidential 1 © 2013 Cisco System Inc. All rights reserved. 1 February 14, 2014 Unity Connection Legal.
IS 4506 Establishing Microsoft SMTP Service.  Overview Introduction to Microsoft SMTP Service SMTP Service features SMTP administration interface SMTP.
Operating Systems Proj.. Background A firewall is an information technology (IT) security device which is configured to permit, deny or proxy data connections.
Unity 5.0 TOI. © 2006 Cisco Systems, Inc. All rights reserved.2 Logging changes Licensing changes 144 port support Michael McCann
© 2015 Cisco System Inc. All rights reserved Cisco Confidential 1 © 2015 Cisco System Inc. All rights reserved. 1 Subject Line Customization for Notifications.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 UC 7.0 Install and Upgrade Changes TOI Josh Rose UCBU Software Engineer.
Page ADP Technology Training. 2 Page2 Confidential Copyright © 2007 Pearson Education, Inc. and/or one or more of its direct or indirect affiliates. All.
VIRTUAL SERVERS Chapter 7. 2 OVERVIEW Exchange Server 2003 virtual servers Virtual servers in a clustering environment Creating additional virtual servers.
Chapter 11 Panko and Panko Business Data Networks and Security, 11 th Edition Copyright © 2016 Pearson Finally, Layer 5!
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Access Control Lists Accessing the WAN – Chapter 5.
Data Virtualization Tutorial… SSL with CIS Web Data Sources
Solving Real-World Problems with Wireshark
REST API Support for Squared UC in Unity Connection 11.5
Instructor Materials Chapter 7: Access Control Lists
Instructor Materials Chapter 5 Providing Network Services
Configuring Attendant Console
Instructor Materials Chapter 9: Testing and Troubleshooting
Cisco Unity Connection
Troubleshooting Network Communications
Cisco Unity Connection
Cisco Unity Connection
Cisco Unity Connection
Cryptography and Network Security Chapter 16
CONNECTION ADVANCE REPLICATION ESTABLISHMENT
Introduction to Networking
Cisco Unity Connection
HPE6-A44 Dumps PDF Scalable WLAN Design and Implementation (SWDI) 8 Exam 100% money back guarantee if you will not clear your exam. Are You Worried About.
Dumps
Chapter 4: Access Control Lists (ACLs)
Cisco Actual Exam Dumps - Valid Cisco Questions Answers - Realexamdumps.com
Get Cisco Exam Real Questions - Cisco Dumps Dumps4Download.co.in.
Cisco Unity Connection Logon Session Limit – TUI/VUI
Chapter 4 Core TCP/IP Protocols
Cisco Unity Connection Disable Inactive Users Accounts
Cisco Unity Connection Read-only CLI
Cisco Unity Connection Customized Log-on Message
Application Layer Functionality and Protocols
Cisco Unity Connection Common PIN
Cisco Unity Connection
Cisco Unity Connection -
Cisco Unity Connection Auto Advance to Next Message After Forward
Managing a Distributed Environment
IEEE MEDIA INDEPENDENT HANDOVER DCN: xx-00-sec
Sending data to EUROSTAT using STATEL and STADIUM web client
NFD Tunnel Authentication
Presentation transcript:

Cisco Unity Connection Minimum TLS Version Support EDCS - 11528243 JAN 01 2017

Notice The information in this presentation is provided under Non-Disclosure agreement and should be treated as Cisco Confidential. Under no circumstances is this information to be shared further without the express consent of Cisco. Any roadmap item is subject to change at the sole discretion of Cisco, and Cisco will have no liability for delay in the delivery or failure to deliver any of the products or features set forth in this document.

Abbreviations CLI – Command Line Interface CUC – Cisco Unity Connection TLS – Transport Layer Security

Agenda Introduction What’s New Configuration Demo Troubleshooting Tips References

Introduction

Introduction Cisco Collaboration Products use TLSv1.0, transport layer encryption for signaling and client server communication which is no longer considered as secure. Hence Products are required to support TLSv1.2 and restrict TLS negotiation over a less secure encryption version (e.g., TLSv1.0) Example: If a browser on TLSv1.0 tries to connect to a server that’s supports TLSv1.2, then browser will not be able to establish connection with the server

What's New CUC already supports TLSv1.0, TLSv1.1,TLSv1.2 . However, there was no way to restrict TLS negotiations to a minimum TLS version. Release 12.0 onwards, System Administrator can configure minimum TLS version. It can be configured via admin CLI command, admin: set tls min-version <tls minVersion> Once “minimum TLS version” is set, all negotiations will happens only if peer supports Configured TLS version Or, Higher version This is applicable for inbound interfaces supported by CUC. For list of all supported Interfaces, refer “IP Communications Required by Cisco Unity Connection” Chapter of “Security Guide for Cisco Unity Connection Release 12.x “ available at Chapter https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/11x/security/b_12xcucsecx/b_12xcucsecx_chapter_00.html

Configuration

Configuring Minimum TLS version To configure minimum TLS version, use below CLI admin: set tls min-version <tls minVersion> Where value for ‘tls minVersion’ can either be 1.0 or 1.1 or 1.2 Example: set tls min-version 1.1 Note: On Cluster, above CLI MUST be executed on both nodes explicitly

Demo

Scenario 1:Connect Server (TLSv1.2) with any browser on TLSv1.2 Set TLS version as “TLSv1.2” in CUC, reboot the system Check TLS version with CLI, admin: show tls min-version Connect any browser (TLSv1.2) to server Wireshark Snapshot : Handshaking is successful

Scenario 2:Connect Server (TLSv1.1) with any browser on TLSv1.0 Set TLS version as “TLSv1.1” in CUC, reboot the system Check TLS version with CLI, admin: show tls min-version Connect any browser (TLSv1.0) to server . Below error can be seen in Internet Explorer. Wireshark Snapshot : Handshaking failed

Troubleshooting Tips

Troubleshooting Annotated Logs Problem Statement 1: If any secure connection fails after setting Minimum TLS version, which was working earlier Action Required: Check if the peer supports TLS version greater than or equal to configured minimum TLS value To verify on CUC, use CLI show tls min-version Annotated Logs Wiki: Annotated diagnostics for Minimum TLS Configuration

References Security Guide For Cisco Unity Connection 12.0 (1) https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/12x/sec urity/b_12xcucsecx.html CLI Reference Guide for Cisco Unified Communications Solutions: http://www.cisco.com/c/en/us/support/unified-communications/ unified- communications-manager-callmanager/products-maintenance-guides- list.html

Supported Interfaces Interface Port Remarks Tomcat 8443,443,8444 Both client and administrative workstations connect to these ports. Supported browsers are Internet Explorer (IE), Mozilla, Chrome Jetty 7443 Notifications of changes to Unity Connection voice messages. Such Interfaces are Single Inbox, Jabber. IMAP 143,993 IMAP Clients such as Outlook make connection with Unity SMTP 25 SMTP Clients such as Thunderbird make connection with Unity SIP 5061-5199 Unity Connection SIP Control Traffic handled by conversation manager. Supported clients such as Call Manager. LDAP 636 LDAP is such outbound interface, which is honoring TLS version changed at unity connection.