-
- Using VMware vSphere With Your System
- Networking Checklist For Your System
- Deploying a System Automatically
- Deploying a System Manually
- Configuring Your Mail Server, Time Zone, and Locale
- Altering the System After Installation
- Adding a High Availability System
- Expanding Your System to a Larger System Size
- Updating the System
- Configuring Your Company Information
- Configuring Your Branding Settings
- Configuring Your Meeting Settings
- About Configuring Your Audio Settings
- Configuring Your Video Settings
- Configuring Your Mobile Settings
- Configuring Quality of Service (QoS)
- Configuring Passwords
- Configuring Your Email Settings
- Configuring Your Download Settings
- Managing Certificates
- Generating SSL Certificates
- Importing SSO IdP Certificates
- Importing Secure Teleconferencing Certificates
- Configuring User Session Security
- Configuring Federated Single Sign-On (SSO) Settings
- Configuring Your Cloud Features
- Configuring Virtual Machine Security
Configuring Settings
This module describes how to configure your settings.
- Configuring Your Company Information
- Configuring Your Branding Settings
- Configuring Your Meeting Settings
- About Configuring Your Audio Settings
- Configuring Your Video Settings
- Configuring Your Mobile Settings
- Configuring Quality of Service (QoS)
- Configuring Passwords
- Configuring Your Email Settings
- Configuring Your Download Settings
- Managing Certificates
- Generating SSL Certificates
- Importing SSO IdP Certificates
- Importing Secure Teleconferencing Certificates
- Configuring User Session Security
- Configuring Federated Single Sign-On (SSO) Settings
- Configuring Your Cloud Features
- Configuring Virtual Machine Security
Configuring Your Company Information
Configuring Your Branding Settings
Prepare the following before configuring your branding settings:
| Step 1 | Sign in to the Administration site. | ||||||||||||||
| Step 2 | Select Settings > Branding. | ||||||||||||||
| Step 3 | Complete the fields on the page and select Save.
|
Removing a Company Logo
Create a transparent 120x32 PNG or GIF file.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Settings > Branding. |
| Step 3 | For the Company Logo field, select Browse and choose your transparent 120x32 PNG or GIF file. |
| Step 4 | Select Save. Your previous company logo is replaced by your blank PNG or GIF file. Confirm that the original logo has been removed. |
Configuring Your Meeting Settings
Configure your meeting settings to control which features participants can use. Configure the following features:
- Join meeting settings
-
Maximum
participants per meeting (meeting size)

Note
This setting is limited by the system size configured during deployment. See Confirming the Size of Your System for more information.
- Participant privileges
| Step 1 | Sign in to the Administration site. | ||||||||||
| Step 2 | Select Settings > Meetings. | ||||||||||
| Step 3 | In the Join
meeting settings section, select your options.
Default settings are Allow participants to join meetings before host, Allow participants to join teleconference before host, and First participant to join will be the presenter. Participants can join meetings up to 15 minutes before the starting time if Allow participants to join Meetings before host and Allow participants to join teleconference before host are selected. Optionally select Anyone can present in the meeting.
| ||||||||||
| Step 4 | Select the maximum
participants per meeting by dragging the slider. The maximum number of
participants for your system is configured during deployment. Following are the
system size settings and corresponding maximum meeting sizes.
| ||||||||||
| Step 5 | In the participant
privileges section, select your options.
Chat,
Polling,
Document
review and presentation, and
Sharing
and Remote Control are selected by default. The selected
participant privileges appear in the users' controls.
Recording is disabled by default. Select Record to record and store meetings on your storage server.
| ||||||||||
| Step 6 | Select Save. |
About Meeting Security
Cisco WebEx Meetings Server enables different meeting security features depending on the following factors:
- User type: host, alternate host, user (signed in), and guest.
- Meeting has a password or no password.
- Password is hidden or visible in the meeting invitation.
- Password is hidden or visible in the email meeting invitation.
- Behavior displayed on the meeting join page (see the following tables).
Table 1 Password is Excluded When Scheduling Your Meeting User Type Password Displayed in Email Invitation and Reminder Meeting Detail Page Host Yes Yes Alternate host Yes Yes Invitee No No Forwarded invitee No No Table 2 Password is Included When Scheduling Your Meeting User Type Password Displayed in Email Invitation and Reminder Meeting Detail Page Host Yes Yes Alternate host Yes Yes Invitee Yes Yes Forwarded invitee Yes Yes - Join before host is on/off.
- Join teleconference before host is on/off.
- First participant can present is on/off.
About Configuring Your Audio Settings
The first time you configure your audio settings, you are guided through the process by a wizard that helps you set your CUCM SIP configuration and call-in access numbers. After you have completed the wizard and configured your initial audio settings, you can configure all other audio settings.
Configuring Your Audio Settings for the First Time
The first time you configure your audio settings, you must specify which features you want and you must configure your CUCM settings. A wizard guides you through the first-time installation procedure.
You must enable teleconferencing and configure CUCM before you proceed with your audio configuration. You must configure CUCM on two systems if you plan to provide teleconferencing high availability. Refer to the Planning Guide for more information. To proceed you must obtain the following information:
- Prepare a list of call-in access numbers that your participants use to call into meetings.
- Your CUCM IP address.
-
(Optional) Obtain a valid secure conferencing certificate if you plan to use TLS/SRTP teleconferencing encryption. See Importing Secure Teleconferencing Certificates for more information. 
Note
This feature is not available in Russia or Turkey.
| Step 1 | Sign in to the Administration site. | ||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||
| Step 3 | Select
.
The Audio page appears and your Current Audio Features are displayed. | ||
| Step 4 | Select
Next.
The SIP Configuration page appears. This page displays the SIP configuration information you need to configure CUCM including the IP address and port number for each server type. | ||
| Step 5 | Select
Next.
The Enable Teleconference: CUCM Setting page appears, displaying your current settings. | ||
| Step 6 | Select
Edit to change your settings.
The CUCM (Cisco Unified Communications Manager) dialog box appears. | ||
| Step 7 | Complete the
fields in the
CUCM
(Cisco Unified Communications Manager) dialog box as follows:
Your new or updated CUCM settings appear on the Enable Teleconference: CUCM Setting page. | ||
| Step 8 | Select
Next.
The Enable Teleconference: Access Number Setting page appears. | ||
| Step 9 | Select
Edit.
The Call-in Access Numbers dialog box appears. | ||
| Step 10 | Select
Add to add a call-in access number.
A line is added in the dialog box for the phone label and number. Each time you select Add, an additional line appears in the dialog box. | ||
| Step 11 | Enter the
Phone
Label and
Phone
Number for each access number that you add and select
Continue after you have finished adding numbers.
Example:Enter "Headquarters" for the Phone Label and "888-555-1212" for the Phone Number. The access numbers you entered are added to your system and you are returned to the Enable Teleconference: Access Number Setting page. The page now indicates how many access numbers have been configured. | ||
| Step 12 | Select
Save.
The wizard informs you that you have successfully configured your teleconferencing features. | ||
| Step 13 | (Optional) Enter a display name in the Display Name dialog box. | ||
| Step 14 | (Optional) Enter a
valid caller ID in the
Caller
ID dialog box.
| ||
| Step 15 | (Optional)
Configure your WebEx Call Me setting (Default: Press 1 to connect to meeting). Optionally select
this option to bypass the requirement to press
1 to connect
to a meeting.
| ||
| Step 16 | (Optional) Select your Telephone entry and exit tone. | ||
| Step 17 | (Optional) If
IPv6 is configured on your system, set your
IPv6
Teleconferencing setting to
On or
Off. (Default: Off. A setting
of
Off indicates that IPv4 is the setting.)
| ||
| Step 18 | Select the System Audio Language users hear when they dial in to the audio portion of a Cisco WebEx meeting or when they use the Call Me service. | ||
| Step 19 | Select Save. | ||
| Step 20 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Configuring Your Audio Settings
If you have not already configured your audio settings, see the Configuring Your Audio Settings for the First Time section.
| Step 1 | Sign in to the Administration site. | ||||||||||||||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||||||||||||||
| Step 3 | Select Settings > Audio. | ||||||||||||||
| Step 4 | Configure your
audio feature settings.
| ||||||||||||||
| Step 5 | In the Edit
Teleconference Settings section, select the
Edit link under CUCM (Cisco Unified Communications
Manager) to change your settings.
The CUCM (Cisco Unified Communications Manager) dialog box appears. Complete the fields and select Continue. | ||||||||||||||
| Step 6 | In the Edit
Teleconference Settings section, select the
Edit link under Call-In Access Numbers to add,
change, or delete your access numbers.
| ||||||||||||||
| Step 7 | Enter a display name in the Display Name dialog box. | ||||||||||||||
| Step 8 | Enter a valid
caller ID in the
Caller
ID dialog box.
| ||||||||||||||
| Step 9 | Configure your
WebEx Call Me setting (Default: Press 1 to connect to meeting). Optionally select
this option to bypass the requirement to press
1 to connect
to a meeting.
| ||||||||||||||
| Step 10 | Select your Telephone entry and exit tone. | ||||||||||||||
| Step 11 | If IPv6 is
configured on your system, set your
IPv6
Teleconferencing setting to
On or
Off. (Default: Off. A setting
of
Off indicates that IPv4 is the setting.)
| ||||||||||||||
| Step 12 | Select Save. | ||||||||||||||
| Step 13 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Configuring Your Video Settings
Configuring Your Mobile Settings
![]() Note | Android is not supported in Cisco WebEx Meetings Server 1.5 and earlier. |
To configure mobile settings you must add public access on your system during deployment. See Adding Public Access to Your System for more information.
Note that if your system is configured to permit more than one call-in access number, the system assumes that the first number is a toll-free access number and the mobile app defaults to attempting this number first. The app will not connect if this number is not reachable from the mobile network. Make sure that this number is accessible from the mobile network.
Configuring Quality of Service (QoS)
Differentiated Services (DiffServ) code point (DSCP) settings determine the QoS for the audio and video media signaling, as defined in RFC 2475. Cisco recommends that you retain the default value. The other values are available for the rare instances when the network requires a different DSCP setting. For more information, see the "Network Infrastructure" chapter of the Cisco Unified Communications Solution Reference Network Design (SRND) that applies to your version of Cisco Unified Communications Manager at http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_implementation_design_guides_list.html.
Following are the default values:
About QoS Marking
QoS Marking on Cisco WebEx Meetings Server Systems With Traffic Moving Through an Internet Reverse Proxy Server
| Traffic | QoS Marking |
|---|---|
| SIP Audio—media—CWMS to Endpoint | Yes |
| SIP Audio—signalling—CWMS to Endpoint | Yes |
| PC Audio—media—CWMS to Client | No |
| PC Audio—signalling—CWMS to Client | No |
| PC Audio—media—Client to CWMS | No |
| PC Audio—signalling—Client to CWMS | No |
| PC Video—media—CWMS to Client | No |
| PC Video—signalling—CWMS to Client | No |
| PC Video—media—Client to CWMS | No |
| PC Video—signalling—Client to CWMS | No |
QoS Marking on Cisco WebEx Meetings Server Systems With No Traffic Moving Through an Internet Reverse Proxy Server
| Traffic | QoS Marking |
|---|---|
| SIP Audio—media—CWMS to Endpoint | Yes |
| SIP Audio—signalling—CWMS to Endpoint | Yes |
| PC Audio—media—CWMS to Client | Yes |
| PC Audio—signalling—CWMS to Client | Yes |
| PC Audio—media—Client to CWMS | No |
| PC Audio—signalling—Client to CWMS | No |
| PC Video—media—CWMS to Client | Yes |
| PC Video—signalling—CWMS to Client | Yes |
| PC Video—media—Client to CWMS | No |
| PC Video—signalling—Client to CWMS | No |
Configuring Passwords
You can configure password settings for the following:
- General Passwords—Controls password expiration periods and enables you to force users to change their passwords either immediately or at a specified interval.
- User Passwords—Enables you to configure password strength for user accounts including mixed case, length, character types and usage, dynamic web page text controls, and setting up a list of unacceptable passwords.
- Meeting Passwords—Enables you to enforce password usage for meetings and to configure password strength for meetings including mixed case, length, character types and usage, dynamic web page text controls, and setting up a list of unacceptable passwords.
![]() Note | If SSO is enabled on your system, the settings on the General Password and User Password pages and the password change controls on the Edit User page no longer apply to host accounts. |
- Configuring Your General Password Settings
- Configuring Your User Password Settings
- Configuring Your Meeting Passwords
Configuring Your General Password Settings
Your general password settings enable you to configure account deactivation and password age limitations. All password settings on this page are optional and can be toggled on (checked) or off (unchecked).
| Step 1 | Sign in to the Administration site. | ||
| Step 2 | Select Settings > Password Management > General Password. | ||
| Step 3 | (Optional) Select
the
Deactivate
host account after
number day(s) of inactivity checkbox and
enter the number of days in the text field. (Default: Checked and set
for 90 days)
If you use the default setting, a user is deactivated if he or she has not hosted or scheduled a meeting for 90 consecutive days.
| ||
| Step 4 | (Optional) Select the Force all users to change password every number day(s) checkbox and enter the number of days in the text field. (Default: Unchecked) | ||
| Step 5 | (Optional) Select Force all users to change password on next login. (Default: Unchecked) | ||
| Step 6 | Select Save. |
Configuring Your User Password Settings
Configure your user password requirements and limitations.
| Step 1 | Sign in to the Administration site. | ||||||||||||||||||||||
| Step 2 | Select Settings > Password Management > User Password. | ||||||||||||||||||||||
| Step 3 | Change your user password settings by configuring the fields on the page.
| ||||||||||||||||||||||
| Step 4 | Select Save. |
Configuring Your Meeting Passwords
Use this feature to configure meeting password parameters. The following table describes which users must enter a password when a meeting is configured with one.
| Password Configured | Password Excluded from Email Invitation | Meeting Creator Signed In | Host Signed In | Invitee Signed In | Guest Signed In | Guest Not Signed In |
|---|---|---|---|---|---|---|
| No | n/a | Password not required. | Password not required. | Password not required. | Password not required. | Password not required. |
| Yes | Yes | Password not required. | Password not required. | Password not required. | Password required. | Password required. |
| Yes | No | Password not required. | Password not required. | Password not required. | Password required. Password can be prefilled. | Password required. Password can be prefilled. |
| Step 1 | Sign in to the Administration site. | ||||||||||||||||||||||||
| Step 2 | Select Settings > Password Management > Meeting Password. | ||||||||||||||||||||||||
| Step 3 | Change your meeting password settings by configuring the fields on the page.
| ||||||||||||||||||||||||
| Step 4 | Select Save. |
Configuring Your Email Settings
You can configure your email settings and templates. Your email templates have default settings that you can optionally change.
| Step 1 | Sign in to the Administration site. | ||
| Step 2 | Select
Settings >
Email.
The Variables page opens. | ||
| Step 3 | Enter your
From
Name, your
From Email
Address, your
Reply-To email address, and then select
Save.
| ||
| Step 4 | Select
Templates. See
About Email Templates for descriptions of each template
type.
The Templates page appears. Select the Common or Meetings tab. Common is the default. | ||
| Step 5 | To configure email templates, select the desired template link on the Common and Meetings tab. | ||
| Step 6 | Make changes (if
any) to the email template you selected and select
Save.
Example:Select the Account Reactivated template link on the Common tab. Make changes to the fields in the Account Reactivated dialog box and select Save. The default From Name, From Email Address, and Reply-To values are taken from the settings you configure on the Variables page.
|
About Email Templates
Use the email templates to communicate important events to users. Each email template has variables that you must configure. See the table below for descriptions of the variables in each template.
There are two types of email templates:
- Common–Including lost password, host and invitee notifications, recording availability, and other general notices.
- Meetings–Including meeting invitations, cancellations, updates, reminders, and information notices.
| Title | Description | Variables |
|---|---|---|
| AD Activation | Sent to a user after an AD account has been activated. | |
| AD-Sync Failed | Sent to an administrator after a failed synchronization. | |
| AD-Sync Success | Sent to an administrator after a successful synchronization. | |
| Account Reactivated | Sent to a user after an administrator reactivates the user's account. | |
| Forgot Password–Password Changed | Sent to a user after he has reset his password from the end-user site. | |
| Forgot Password–Reset Password | Sent to a user after he has reset his password from the end-user site. This email asks the user to create a new password. | |
| PT PCN Meeting Invitation—Invitee | Sent to meeting invitees after a meeting is scheduled using Productivity Tools from a PCN account. | |
| PT PCN Meeting Notification—Host | Sent to a meeting host after a meeting is scheduled using Productivity Tools from a PCN account. | |
| PT—Host Notification | Sent to a meeting host after a meeting is scheduled using Productivity Tools. | |
| PT—Invitee Notification | Sent to meeting invitees after a meeting is scheduled using Productivity Tools. | |
| Recording Available for Host | Sends the host a link to a meeting recording. | |
| SSO Activation Email | Sent after Single Sign-On (SSO) is enabled. | |
| Send Email To All Users | Sends an email to all users on the system. | |
| Setup Cisco WebEx—Android | Informs users about the Cisco WebEx app for Android and provides a download link for the app. | |
| Setup Cisco WebEx—iPhone/iPad | Informs users about the Cisco WebEx app for iPhone/iPad and provides a download link for the app. | |
| Share Recording | Sends selected meeting attendees a link to a meeting recording. | |
| Share Recording from MC | Sends selected meeting attendees a link to a meeting recording. Attendees selected by the host in Meeting Center after selecting Leave Meeting. | |
| Users—Password Changed | Sends users an email when their password has been changed. | |
| Welcome Email | Sent to a new administrator after his or her account is created. |
| Title | Description | Variables |
|---|---|---|
| In-Progress Meeting Invite for Attendee | Sent to users when a host invites them to a meeting while the meeting is in progress. | |
| Instant Meeting Invite for Host | Sent to the host and attendees when the host selects Meet Now. | |
| Meeting Canceled for Attendee | Informs a user that a scheduled meeting has been canceled. | |
| Meeting Canceled for Host | Sent to a meeting's host to confirm cancellation of a meeting. | |
| Meeting Information Updated for Alternate Host | Provides meeting information to the alternate host when the meeting settings have been changed. | |
| Meeting Information Updated for Attendee | Provides meeting information for a meeting invitee when the meeting settings have been changed. | |
| Meeting Information Updated for Host | Provides meeting information to the host when the meeting settings have been changed. | |
| Meeting Reminder for Alternate Host | Sends a meeting reminder to the meeting's alternate host. | |
| Meeting Reminder for Host | Sends a meeting reminder to the meeting's host. | |
| Meeting Rescheduled for Alternate Host | Sends updated meeting information to the alternate host. | |
| Meeting Rescheduled for Attendee | Sends updated meeting information to attendees. | |
| MeetingInfo for Alternate Host | Sends a meeting confirmation to the alternate host. | |
| MeetingInfo for Attendee | Sends a meeting invitation to attendees. | |
| MeetingInfo for Host | Sends a meeting confirmation to the host. | |
| PCN Meeting Auto Reminder—Host | Sends an automatic meeting reminder to the meeting's host (PCN accounts only). | |
| PCN Meeting Invitation—Invitee | Sends a meeting invitation to invitees (PCN accounts only). | |
| PCN Meeting Manual Reminder—Host | Sends a manual meeting reminder to the meeting's host (PCN accounts only). | |
| PCN Meeting Manual Reminder—Invitee | Sends a manual meeting reminder to invitees (PCN accounts only). | |
| PCN Meeting Notification—Host | Sends a meeting notification to the host (PCN accounts only). | |
| PCN Meeting Instant Invitation—Host | Sends an instant meeting notification to the host (PCN accounts only). | |
| PCN Meeting In Progress Invitation—Invitee | Sends an instant meeting notification to an invitee (PCN accounts only). | |
| PCN Meeting Schedule Change—Host | Sends a schedule change notification to the host (PCN accounts only). | |
| PCN Meeting Schedule Change—Invitee | Sends a schedule change notification to an invitee (PCN accounts only). | |
| PCN Meeting Rescheduled—Invitee | Sends a meeting rescheduled notification to an invitee (PCN accounts only). | |
| PCN Meeting Canceled—Host | Sends a meeting cancellation notification to a host (PCN accounts only). | |
| PCN Meeting Canceled—Invitee | Sends a meeting cancellation notification to an invitee (PCN accounts only). |
Configuring Your Download Settings
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Settings > Downloads. |
| Step 3 | Select the Auto update WebEx Productivity Tools check box to configure periodic automatic updates. (Default: checked.) |
| Step 4 | Select your
download method:
If you select Permit users to download WebEx desktop applications, you can select Save to finish your download configuration. No further action is necessary. If you select Manually push WebEx Meetings and Productivity Tools to user’s desktop, proceed to the next step. If you select Manually push WebEx Meetings and Productivity Tools to user’s desktop, the WebEx Meetings Application, Productivity Tools, and WebEx Network Recording Player sections appear on the page. |
| Step 5 | For each
application that you want to download and install, select
Download and select
Save to save a ZIP file to your system that contains
installers for the corresponding application.
Each ZIP file contains application installers for all supported languages and platforms. |
| Step 6 | Select Save to save your download settings. |
About Downloads
This product can be used on Windows PCs where users have administrator privileges and on those that do not. This section provides basic information about downloads. For detailed information on configuring downloads refer to the About Downloads section of the Planning Guide.
On PCs without administrator privileges:
- We recommend that you push the WebEx Meetings application and Productivity Tools to end-user desktops offline before you inform end-users that user accounts have been created for them. This ensures that your users can start and join meetings from their web browsers and Windows desktops the first time they sign in.
- You can acquire the .MSI installers for each from the Administration site at the Settings > Downloads page. See Configuring Your Download Settings for more information.
- If you decide against pushing the applications to your users, they can still access these applications from the end-user download pages. However, if their PCs prohibit installation of downloaded applications, they will not be able to complete the installation process.
- When users join meetings by using their web browser (the WebEx Meetings application can still be downloaded on demand) they can join meetings successfully. In addition, the WebEx Meetings application attempts to perform an installation to speed up the process of starting or joining future meetings. This fails because their PCs do not have administrator privileges.
- Users can download and install the WebEx Meetings application and Productivity Tools from the end-user download pages. No additional administrator action is required.
- Users are advised to install the Productivity Tools the first time they sign in.
- The WebEx Meetings application is downloaded on-demand the first time a user joins a meeting and is installed silently on the user's PC.
Managing Certificates
Certificates are used to ensure secure communication between the components of your system. When your system is first deployed, it is configured with a self-signed certificate. While a self-signed certificate can last for up to five years, we strongly recommend that you configure certificates that are validated by a certificate authority. A certificate authority ensures that communication between your virtual machines is authenticated. Note that you must install a certificate for each virtual machine on your system.
The following certificate types are supported:
- SSL—Required on all systems.
- SSO IdP—For SSO with identity provider (IdP) certificates.
- Secure teleconferencing—Required for TLS teleconferencing. You can configure up to two secure teleconferencing certificates, one for each CUCM system that you choose to configure.
All systems must have a SSL certificate. This product supports the following SSL certificates:
You cannot update your certificates. If you add virtual machines to your system or change any of your existing virtual machines, you must generate new certificates for each virtual machine on your system.
- Your system size has been expanded, resulting in the deployment of new virtual machines. The fully qualified domain names (FQDNs) of these new virtual machines are not present in your original SSL certificate.
- A high-availability system has been added, resulting in the deployment of new virtual machines. The FQDNs of these new virtual machines are not present in your original SSL certificate.
- The Cisco WebEx site URL has changed. This URL is not present in your original SSL certificate.
- The Administration site URL has changed. This URL is not present in your original SSL certificate.
- The FQDN of the administration virtual machine has changed. This FQDN is not present in your original SSL certificate.
- Your current SSL certificate has expired.
If your SSL certificate becomes invalid for any reason, your system will automatically generate new self-signed certificates and you are informed of this change by a global warning message at the top of the Administration site page indicating that SSL has become invalidated.
Generating SSL Certificates
Your system must have a SSL certificate configured. This product supports the following types of SSL certificates:
- Generating a Certificate Signing Request (CSR)
- Importing a SSL Certificate
- Exporting a SSL Certificate
- Downloading Your CSR and Private Key
- Generating a Self-Signed Certificate
- Restoring a SSL Certificate
Generating a Certificate Signing Request (CSR)
| Step 1 | Sign in to the Administration site. | ||||||||||||||||||||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||||||||||||||||||||
| Step 3 | Select Settings > Security > Certificates > Generate CSR. | ||||||||||||||||||||
| Step 4 | Complete the fields on the Generate CSR (Certificate Signing Request) page.
| ||||||||||||||||||||
| Step 5 | Select Generate CSR. The Download CSR dialog box appears. | ||||||||||||||||||||
| Step 6 | Select Download. You receive a ZIP file that contains the CSR and the associated private key. The CSR file is called csr.pem and the private key file is called csr_private_key.pem. | ||||||||||||||||||||
| Step 7 | Back up your system using VMware Data Recovery (vSphere 5.0) or VMware vSphere Data Protection (vSphere 5.1). See Creating a Backup by using VMware vCenter for more information.
| ||||||||||||||||||||
| Step 8 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Importing a SSL Certificate
You can import a SSL certificate using this feature. Cisco WebEx Meetings Server supports X.509 certificates with PEM and DER encoding and PKCS12 Archives.
| Step 1 | Sign in to the Administration site. | ||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||
| Step 3 | Select Settings > Security > Certificates > More Options > Import SSL Certificate/private key. If you already have a certificate installed, the system warns you that importing a new certificate will overwrite it. | ||
| Step 4 | Select Continue. | ||
| Step 5 | Select Browse and choose your certificate file. You must choose an X.509-compliant certificate or certificate chain. Valid types include: You can import a certificate chain using a PKCS#12 file or a single file of PEM blocks. If use a PEM file, It must be formatted as follows:
All the certificates must be uploaded together in one file. You cannot upload one certificate and then add the intermediate certificates later. You might want to upload the intermediate certificates if you are using a certificate authority that uses intermediate certificates and the intermediate certificates are not distributed in their clients. Uploading them will prevent certificate warnings. PKCS#12 files must have a .p12 extension. They should only contain the certificates and private key (optional). | ||
| Step 6 | Select Upload. After you select Upload, the system will determine if your certificate is valid. A certificate can be invalid for the following reasons:
If the certificate is valid, proceed to the next step. If the certificate is invalid, you cannot upload it. You must select a valid certificate before you can continue. | ||
| Step 7 | (Optional) Enter a passphrase in the Passphrase field.
| ||
| Step 8 | Select Continue. Your system imports your SSL certificate and displays it in a scrollable certificate file dialog box. | ||
| Step 9 | Select Done. | ||
| Step 10 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Exporting a SSL Certificate
What to Do Next
Ensure that both administrators and end users are able to sign in to the administration or web pages without seeing any site not trusted browser warnings.
Downloading Your CSR and Private Key
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Settings > Security > More Options > Download CSR. A dialog box appears asking you to save the file, CSR.zip, which contains the CSR and private key. |
| Step 3 | Select a location on your system to save the file and select OK. |
| Step 4 | Back up your private key file, csr-private-key.pem, in the event that you need it later. |
Generating a Self-Signed Certificate
A self signed certificate is automatically generated after you deploy your system. We recommend that you install a certificate that is signed by a certificate authority. You can generate a new self-signed certificate at any time by using this feature.
![]() Note | Users might have problems joining meetings if their system uses a self-signed certificate unless the administrator at the client side has configured his system to use self-signed certificates. |
| Step 1 | Sign in to the Administration site. | ||||||||||||||||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||||||||||||||||
| Step 3 | Select Settings > Security > Certificates > More Options > Generate self-signed certificate. | ||||||||||||||||
| Step 4 | Complete the fields on the General Self Signed Certificate page.
| ||||||||||||||||
| Step 5 | Select Generate Certificate and Private Key.
Your certificate file is generated and displayed. | ||||||||||||||||
| Step 6 | Select Done. | ||||||||||||||||
| Step 7 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Restoring a SSL Certificate
In the event that your certificate becomes invalid or you have performed a disaster recovery on your system, you can restore a SSL certificate using this feature. Cisco WebEx Meetings Server supports X.509 certificates with PEM and DER encoding and PKCS12 Archives.
| Step 1 | Sign in to the Administration site. | ||
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. | ||
| Step 3 | Select Settings > Security > Certificates > More Options > Import SSL Certificate. If you already have a certificate installed, the system warns you that importing a new certificate will overwrite it. | ||
| Step 4 | Select Continue. | ||
| Step 5 | Select Browse and choose your certificate file. You must choose an X.509-compliant certificate or certificate chain. Valid types include: You can import a certificate chain using a PKCS#12 file or a single file of PEM blocks. If use a PEM file, It must be formatted as follows:
All the certificates must be uploaded together in one file. You cannot upload one certificate and then add the intermediate certificates later. You might want to upload the intermediate certificates if you are using a certificate authority that uses intermediate certificates and the intermediate certificates are not distributed in their clients. Uploading them will prevent certificate warnings. PKCS#12 files must have a .p12 extension. They should only contain the certificates and private key (optional). | ||
| Step 6 | Select Upload. After you select Upload, the system will determine if your certificate is valid. A certificate can be invalid for the following reasons:
If the certificate is valid, proceed to the next step. If the certificate is invalid, you cannot upload it. You must select a valid certificate before you can continue. | ||
| Step 7 | (Optional) Enter a passphrase in the Passphrase field.
| ||
| Step 8 | Select Continue. Your system imports your SSL certificate and displays it in a scrollable certificate file dialog box. | ||
| Step 9 | Select Continue on the SSL Certificate page to complete the import. | ||
| Step 10 | Select Done. | ||
| Step 11 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Importing SSO IdP Certificates
Importing Secure Teleconferencing Certificates
Secure teleconferencing certificates are only required if TLS conferencing is enabled. If TLS conferencing is not enabled, this option is not available.
Secure teleconferencing certificates are required for your CUCM servers when TLS is selected as the transport type in your audio settings. See About Configuring Your Audio Settings for more information.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. |
| Step 3 | Select
Settings >
Security >
Certificates.
If secure teleconferencing certificates are required, an Import Certificate button is shown for each CUCM server that must be configured. |
| Step 4 | Select Import Certificate for CUCM 1. |
| Step 5 | Enter a certificate name. |
| Step 6 | Select Browse and choose your certificate file. |
| Step 7 | Select
Upload.
After you select Upload, the system will determine if your certificate is valid. If the certificate is valid, proceed to the next step. If the certificate is invalid, you cannot upload it. You must select a valid certificate before you can continue. |
| Step 8 | Select
Continue.
Your system imports your SSL certificate and displays it in a scrollable certificate file dialog box. You are notified that you have imported an SSL certificate. |
| Step 9 | Select Done. |
| Step 10 | Return to step 4 and repeat the process for your CUCM 2 server. |
| Step 11 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Configuring User Session Security
| Step 1 | Sign in to the Administration site. | ||||||||
| Step 2 | Select Settings > Security > User Sessions. | ||||||||
| Step 3 | Complete the fields on the User Sessions page to set the web page expiration time.
| ||||||||
| Step 4 | Select Save. |
Configuring Federated Single Sign-On (SSO) Settings
Configuring SSO enables your end-users to sign into the system using their corporate credentials, thereby giving you a way to integrate the product with your corporate directory. You may also configure SSO to create or manage user accounts on the fly when users attempt to sign in.
![]() Note | Configuring SSO can be a complex operation and we strongly recommend that you contact your Cisco Channel Partner or Cisco Advanced Services before you continue. |
Before you enable the federated single sign-on feature, you must generate a set of public and private keys and an X.509 certificate that contains the public key. Once you have a public key or certificate, you must upload it in the Managing Certificates section. 
NoteAfter you have enabled SSO, user credentials are managed by your corporate authentication system. Certain password management features no longer apply to your users. See Configuring Passwords and Editing Users for more information. Note that even though administrators are also end users, administrators do not sign in using SSO. They sign in using their administrator credentials for this product.
- Configure a SSO IdP certificate to use this feature. See Importing SSO IdP Certificates for more information.
| Step 1 | Sign in to the Administration site. | ||||||||||||||||||||||||||||||||||||||||||||||||
| Step 2 | Select Settings > Security > Federated SSO. | ||||||||||||||||||||||||||||||||||||||||||||||||
| Step 3 | After you have generated public and private keys and an X.509 certificate, as described in the pre-requisites, select Continue. | ||||||||||||||||||||||||||||||||||||||||||||||||
| Step 4 | Select your initiation method:
| ||||||||||||||||||||||||||||||||||||||||||||||||
| Step 5 | Complete the fields and select your options on the SSO Configuration page:
| ||||||||||||||||||||||||||||||||||||||||||||||||
| Step 6 | Select Enable SSO. The Review SSO Settings page appears. Review your settings and select Save. |
Disabling SSO
Disabling SSO will disable your users' ability to sign in with their company credentials. Make sure you inform your users that you are disabling SSO and that they can still sign in with their Cisco WebEx credentials.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Settings > Security > Federated SSO. |
| Step 3 | Find the sentence, "If you would like to disable SSO please click here." Select the click here link. |
| Step 4 | Select Disable SSO to confirm. The Federated SSO page appears with a banner that confirms you have disabled SSO. |
Configuring Your Cloud Features
![]() Note | Your system supports Cisco WebEx SaaS releases WBS27, WBS28, and Cisco WebEx Meetings 1.2. |
Configuring Virtual Machine Security
Your virtual machine security features include the ability to update your encryption keys and enable or disable FIPS-compliant encryption.
- Updating Your Encryption Keys
- About FIPS
- Enabling FIPS Compliant Encryption
- Disabling FIPS Compliant Encryption
Updating Your Encryption Keys
Cisco WebEx Meetings Server uses internally generated encryption keys to secure all communications between the virtual machines on your system. Use this feature to update your encryption keys periodically.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. |
| Step 3 | Select Settings > Security > Virtual Machines. |
| Step 4 | Select Update Encryption Keys. |
| Step 5 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
About FIPS
FIPS 140 Requirements
At a very high level, the FIPS 140 requirements apply to the following module characteristics:
- Implementation of FIPS-approved algorithms
- Specific management of the key life cycle
- Approved generation of random numbers
- Self-tests of cryptographic algorithms, image integrity, and random number generators (RNGs)
Cisco WebEx Meetings Server uses CiscoSSL 2.0 to achieve FIPS 140-2 Level 2 compliance.
With FIPS Enabled
Enabling FIPS might result in reduced compatibility with popular web-browsers and operating systems. Symptoms might include, but are not limited to, problems signing into the system, 404 errors, and starting and joining meetings.
Cisco recommends that you take the following actions:
- Ensure that your Windows PCs are running at least Windows XP SP3 or above.
- Update all Windows computers to Microsoft Internet Explorer 8 or above regardless of whether your users' desired web browser is Internet Explorer, Mozilla Firefox, or Google Chrome. Your users must provide Internet Explorer 8 on all computers because our FIPS-enabled clients (Cisco WebEx Meetings, Productivity Tools, and WebEx Recording Player) use FIPS-enabled system libraries that are only available on Internet Explorer 8 and above.
- Configure Internet settings on all user computers to TLS encryption. On your PC desktop, select Control Panel > Internet Options > Advanced > Security > Use TLS 1.0 and Use TLS 1.2. We recommend selecting both options for maximum compatibility but you must at least select Use TLS 1.0.
- If your users plan to host meetings for guests (for example, people who do not work for your company) you must inform your guest users to manually update their operating systems and browsers as described above before they join your meetings. If they do not perform the above steps, they might experience compatibility issues. We recommend that you include the above instructions in your meeting invitations. You can do this by editing the appropriate meeting invitations available on your Administration site at Settings > Email > Templates.
Enabling FIPS Compliant Encryption
Use this feature to enable your Federal Information Processing Standard (FIPS) compliant encryption setting.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. |
| Step 3 | Select Settings > Security > Virtual Machines. |
| Step 4 | Select Enable to enable FIPS compliant encryption and Continue to confirm. FIPS compliant encryption is configured on your system. |
| Step 5 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Disabling FIPS Compliant Encryption
Use this feature to disable Federal Information Processing Standard (FIPS) compliant encryption on your system.
| Step 1 | Sign in to the Administration site. |
| Step 2 | Select Turn On Maintenance Mode and Continue to confirm. |
| Step 3 | Select Settings > Security > Virtual Machines. |
| Step 4 | Select Disable to disable FIPS compliant encryption and Continue to confirm. FIPS compliant encryption is disabled on your system. |
| Step 5 | Select Turn Off Maintenance Mode and Continue to confirm. Your system restarts after you turn off maintenance mode. You can sign back into the Administration site after restart is complete. |
Feedback