Table of Contents

CUBE - TLS

Generating CSR

We need to create a CSR which will be signed by a CA (and likely also an intermediate CA). Steps:

Then once you have the PEM file returned - which should contain the signed cert, as well as the inter and root CAs) you need to import the intermediate and CA certs (in that order and both together)

Finally import the actual certificate for that router.

CUCM-CUBE TLS SIP Trunk

What we want - TLS between CUBE and CUCM - but not have SRTP - Note enabling SRTP can have a 75% impact on sizing on the 4431s)

Reference: https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html

Summary Steps

Detailed Steps

CUBE Config

Create Trustpoint for self signed CUBE certificate
CUBE-A(config)#crypto pki trustpoint CUBE-A.mydomain.com
CUBE-A(ca-trustpoint)# enrollment selfsigned
CUBE-A(ca-trustpoint)# serial-number none
CUBE-A(ca-trustpoint)# fqdn none
CUBE-A(ca-trustpoint)# ip-address none
CUBE-A(ca-trustpoint)# revocation-check none
CUBE-A(ca-trustpoint)# subject-name cn=CUBE-A.mydomain.com
CUBE-A(ca-trustpoint)# rsakeypair CUBE-A.mydomain.com

Create the certificate for the CUBE

CUBE-A(config)#crypto pki enroll CUBE-A.mydomain.com
% The fully-qualified domain name will not be included in the certificate
Generate Self Signed Router Certificate? [yes/no]: yes

Router Self Signed Certificate successfully created

CUBE-A(config)#

Export the Self Signed Certificate

CUBE-A(config)#crypto pki export CUBE-A.mydomain.com pem terminal
% Self-signed CA certificate:
-----BEGIN CERTIFICATE-----
MIICNDCCAZ2gAwIBAgIBATANBgkqhkiG9w0BAQUFADAjMSEwHwYDVQQDExhDVUJF
LlhakjhmAgMBAAGjeDB2MA8GA1UdEwEB/MAgMBAAGjeDB2MA8GA1UdEwEB/xMDAw
MDAwWjAjMSEwHwYDVQQDExhDVUJFLUEudmhpaGVhbHRoY2FyZS5uZXQwgZ8wDQYJ
KoZIhvcNABaNanaQgY0AMIGJAoGBALF79FOfyGAHaJgRuhehzSFX6/Gop8/vwGuq
TOxWLySHaZ/5NpD4K67DoZJriDAfBC/j1KLkF6YK9LeFvEGkvgc0y/PjZx3/wMTj
k059THE0CNvvMCxZY66NXvsWlBajX1dhcd6LdevPSPe8UpR/hmdF0Iyuy3HTzKzk
r7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEB/wQFMAMBAf8wIwYDVR0RBBwwGoIYQ1VC
RS1BLnZoaWhlYWx0aGNhcmUubmV0MB8GA1UdIwQYMBaAFJDTla2gcpXY2D0OQ7Tk
a2gcpXY2D0OQTANBgkqhkiG9w0Br7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEBIyuJv
AQUFAAOBgQAgSpp2KdMoraJLhDPqMxJG+WJFMVeM4PXI8AcnjAPvvT72vXZu1hx7
G98QZjaCPCImJNnJAYJuQ2Ivp5IQ0EJv0AynGEwISX0cZ+8GBVe1qF7j2Dpsw8pb
izDlGeJ5yx2mxi2AyndVhnXfpU6b2GKMz46FmzZfSeqW3QUzTLNM7w==
-----END CERTIFICATE-----

% General Purpose Certificate:
-----BEGIN CERTIFICATE-----
MIICNDCCAZ2gAwIBAgIBATANBgkqhkiG9w0BAQUFADAjMSEwHwYDVQQDExhDVUJF
LlhakjhmAgMBAAGjeDB2MA8GA1UdEwEB/MAgMBAAGjeDB2MA8GA1UdEwEB/xMDAw
MDAwWjAjMSEwHwYDVQQDExhDVUJFLUEudmhpaGVhbHRoY2FyZS5uZXQwgZ8wDQYJ
KoZIhvcNABaNanaQgY0AMIGJAoGBALF79FOfyGAHaJgRuhehzSFX6/Gop8/vwGuq
TOxWLySHaZ/5NpD4K67DoZJriDAfBC/j1KLkF6YK9LeFvEGkvgc0y/PjZx3/wMTj
k059THE0CNvvMCxZY66NXvsWlBajX1dhcd6LdevPSPe8UpR/hmdF0Iyuy3HTzKzk
r7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEB/wQFMAMBAf8wIwYDVR0RBBwwGoIYQ1VC
RS1BLnZoaWhlYWx0aGNhcmUubmV0MB8GA1UdIwQYMBaAFJDTla2gcpXY2D0OQ7Tk
a2gcpXY2D0OQTANBgkqhkiG9w0Br7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEBIyuJv
AQUFAAOBgQAgSpp2KdMoraJLhDPqMxJG+WJFMVeM4PXI8AcnjAPvvT72vXZu1hx7
G98QZjaCPCImJNnJAYJuQ2Ivp5IQ0EJv0AynGEwISX0cZ+8GBVe1qF7j2Dpsw8pb
izDlGeJ5yx2mxi2AyndVhnXfpU6b2GKMz46FmzZfSeqW3QUzTLNM7w==
-----END CERTIFICATE-----

CUBE-A(config)#

Import all CallManager Nodes Certs onto the CUBE which will send or receive calls

Example below for one CUCM Node

Enter configuration commands, one per line.  End with CNTL/Z.
CUBE-A(config)#crypto pki trustpoint uc-cucm-sub-1a.mydomain.com
CUBE-A(ca-trustpoint)# enrollment terminal
CUBE-A(ca-trustpoint)# revocation-check none
CUBE-A(config)#crypto pki authenticate uc-cucm-sub-1a.mydomain.com

Enter the base 64 encoded CA certificate.
End with a blank line or the word "quit" on a line by itself

-----BEGIN CERTIFICATE-----
MIID0TCCArmgAwIBAgIQWgh0k4uyHCX1X6MzuUVPJDANBgkqhkiG9w0BAQsFADB9
MQswCQYDVQQGEwJJRTEMMAoGA1UECgwDVkhJMREwDwYDVQQLDAhUZWxlY29tczEp
MCcGA1UEAwwgVUMtQ1VDTS1TVUItMUEudmhpaGVhbHRoY2FyZS5uZXQxETAPBgNV
BAgMCExlaW5zdGVyMQ8wDQYDVQQHDAZEdWJsaW4wHhcNMTYwODA4MTUxNDAzWhcN
MjEwODA3MTUxNDAyWjB9MQswCQYDVQQGEwJJRTEMMAoGA1UECgwDVkhJMREwDwYD
Vbott0mbAnNaBaNaNasB00PBo5sEAwwgVUMtQ1VDTS1TVUItMUEudmhpaGVhbHRo
Y2FyZS5uZXQxETAPBgNVBAgMCExlaW5zdGVyMQ8wDQYDVQQHDAZEdWJsaW4wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCzXdBYGES6JwDXXtlNPLh3TI8L
spH0+pA7Zc5GdjSTUNGqcLqNI+bOD8iynIo2wXyaK8D30qkP4H58uGHZqeWUUBTD
ZX/mei7fNKpXn0PfNUaj/ne8DhovIJnI1jrtBcV6zsxW7LRnew2yuXhZ13+LlpS5
se6hdnXcYSnh5hQcIuMRTU/E6B+OI2Xkd2W9SmeznJGwXvYYJwRT7yo8i5WYHb/b
mXzIzeW41gc23vkyU5dNeDwUNfets8vNAN9PwM6559jSCGQgX20WetnlQn5NHk25
SQh3XoAZdIy3ZQFFkEYIAE6DhNjkKeqATC6kuLVSWVm4mosu8pT6Mlp+L9XzAgMB
AAGjTTBLMAsGA1UdDwQEAwICtDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUH
AwIwHQYDVR0OBBYEFJm6E+cGQACVadgUvdqneg5n++3PMA0GCSqGSIb3DQEBCwUA
A4IBAQCzU/OjoZGYBOPULf4OkxW3bOmI5zhpbXm3BWCo20QeIfTPaM/v85n5eYN9
BBNlawztvottcR7YH4yhz5wMn5ICPWiqacEumIfoxnz9v7hQeSDpgJ0MoMHarFgB
ThPuDsPZQV5qK73KIm0DNNcbFO1G1OiEcXenKqEIhnSvPxRZD8KZOWlc2OhWhPLk
l6MOzMzEcQRDdMY5TpoWj4OBtrGIRFbJ1IfDb3AtMKyxkQF4lLvUy7K8skjymr8H
qL6hJqkwlsCPiVu6Oi4Q9Y85kl8m3MwA6f367rc2k+iIPAt3h7QwldgC2d5VJFJk
hawnxjo0viK5yXidux79c/fu++3r
-----END CERTIFICATE-----

Certificate has the following attributes:
       Fingerprint MD5: FFA5B2F6 7058E607 AAE0F1BC 8D1C1972
      Fingerprint SHA1: B7332EB9 1EB2BEDB 9F7B1963 7A219D1D BE5F4125

% Do you accept this certificate? [yes/no]: yes
Trustpoint CA certificate accepted.
% Certificate successfully imported

Enable Security License

Note: Make sure you are entitled to have a security license on the CUBE - if not purchase one. This command requires the CUBE to be reloaded to take effect.

CUBE-A(config)#license boot level securityk9
% use 'write' command to make license boot config take effect on next boot

CUBE-A(config)#
CUBE-A#wr

Configure SIP to use the Trustpoint Self Signed Certificate

CUBE-A(config)#sip-ua
CUBE-A(config-sip-ua)#crypto signaling default trustpoint CUBE-A.mydomain.com

Configure a TLS SIP Options Profile

!
voice class sip-options-keepalive 3
 description ### TLS SIP options PING ###
 down-interval 10
 up-interval 10
 retry 3
 transport tcp tls
!

Update Dial-peers to/from CUCM

dial-peer voice 2500 voip
 description ### to CUCM ###
 translation-profile outgoing CUCM
 huntstop
 destination-pattern +3530000000000
 session protocol sipv2
 session transport tcp tls
 session server-group 2000
 voice-class codec 1
 voice-class sip options-keepalive profile 3
 voice-class sip bind control source-interface GigabitEthernet0/0/2
 voice-class sip bind media source-interface GigabitEthernet0/0/2
 dtmf-relay rtp-nte
 no vad
!
dial-peer voice 9500 voip
 description ### from CUCM ###
 session protocol sipv2
 session transport tcp tls
 destination dpg 9000
 incoming uri via CUCM
 voice-class codec 1
 voice-class sip early-offer forced
 voice-class sip bind control source-interface GigabitEthernet0/0/2
 voice-class sip bind media source-interface GigabitEthernet0/0/2
 dtmf-relay rtp-nte
 no vad

CUCM Config

Upload CUBE Self Signed Cert to CUCM

Make sure to upload as a CallManager-Trust Certificate - as per below screenshot.

The GUI informs you to restart the CUCM Service after uploading this certificate, but you do not need in this case

Create SIP Security Profile for each CUBE

Update CUCM SIP Trunk

Troubleshooting Commands

debug crypto pki api
debug crypto pki callbacks
debug crypto pki messages
debug crypto pki transactions
debug ssl openssl errors
debug ssl openssl msg
debug ssl openssl states
debug ip tcp transactions
debug ccsip verbose

Regeneration of Certs

After regeneration of CallManager Certs