cucm and ip phones

Boris Lytochkin lytboris at yandex-team.ru
Mon Sep 25 14:06:30 CEST 2017


Hi.

Cisco IP phones (all modern) have Manufacturer Installed Certificate (MIC) so you can authenticate them using EAP-TLS.
You need to import their crcam* cert chains into your FreeRADIUS installation from https://www.cisco.com/security/pki/

On 25.09.2017 14:52, Vacheslav wrote:
> Peace, I configured my ip phones to use mab, but I read that with Radius it is possible to authenticate capable ip phones with tls.
> I searched the internet on how to do it but found almost nothing.
> Should I import the created self signed certificates from the freeradius server to the cucm? Or is that I have to export the cucm certificates to the cert directory of the freeradius server?
> Anyone has experience in configuring cucm with dot1x?
>
>
>
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

-- 
Boris Lytochkin
Yandex NOC
+7 (495) 739 70 00 ext. 7671



More information about the Freeradius-Users mailing list