D15362.16 DX70 and DX80 Administrator Guide CE9.13, JUNE 2020.
www.cisco.com — Copyright © 2020 Cisco Systems, Inc. All rights reserved.
61
Cisco Webex DX70 and DX80
Administrator Guide
Manage the lists of trusted certificate authorities - CAs
Certificate validation may be required when using TLS (Transport
Layer Security).
You can configure the device to demand that a server or client
presents its certificate before communication is set up. The
device uses the certificate to verify the authenticity of the
server or client. If authentication fails, the connection will not be
established.
The certificate (text file) must be signed by a trusted Certificate
Authority (CA). Lists of certificates from trusted CAs reside on the
device.
The CA certificate lists
You can check and maintain the lists of trusted CAs from the web
interface of the device:
• Sign in to the web interface, navigate to
Security > Certificate
Authorities
. There is one tab for each CA list.
These are the CA lists:
•
Preinstalled
: Pre-installed CA certificates that are used to
validate the certificates of external servers (HTTPS and
syslog) that the device communicates with.
•
Collaboration Edge
: Pre-installed CA certificates that are
used to validate the certificates of servers contacted over
the Internet when the device is provisioned by Cisco Unified
Communications Manager (CUCM) via Expressway (also
known as MRA or Edge).
•
Custom
: CA certificates that you have uploaded to the device
yourself. The list must include all CAs that are needed in order
to verify certificates for both logging and other connections, if
those certificates are not already included in the pre-installed
lists.
(page 1 of 4)
Introduction
Configuration
Peripherals
Maintenance
Device settings
Appendices
Configuration