On the computer requiring a certificate, open a Web browser.
Step 2
Enter the URL
http://<name of your Issuing CA server>/certsrv.
Step 3
Select
Enter.
Step 4
Select
Request a Certificate.
Step 5
Select
Advanced certificate request.
Step 6
Select
Create and submit a request to this CA.
Step 7
Select
Other in the Type of Certificate Needed list.
Step 8
In the Name field of the Identifying Information section, enter
the
FQDN. The name must match the name of the
Microsoft OCS, which is
usually the FQDN.
Step 9
In the OID field, type the following OID:
1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2.
Note
A comma separates the two 1s in the middle of the OID.
Step 10
Perform one of the following procedures:
If you are using Windows Certificate Authority 2003, check
Store certificate in the local computer certificatestore in Key Options.
If you are using Windows Certificate Authority 2008, refer to
the workaround described in the Troubleshooting Tips of this topic.
Step 11
Enter a friendly name.
Step 12
Select
Submit.
Step 13
Select Yes
in the Potential Scripting Violation dialog box.
Troubleshooting Tips
If you are using Windows Certificate Authority 2008, you no longer
have the option to store the certificate in the local computer store on the
certificate enrollment page. Perform the following workaround to replace Step
10 in the procedure:
Sign out of the
Microsoft OCS server.
Sign in to the
Microsoft OCS server as
a Local user.
Create the certificate.
Approve the certificate from the CA server.
Export the certificate to a file.
Sign out of the
Microsoft OCS server.
Sign in to the
Microsoft OCS server as
a Domain user.
Import the certificate file using the Certificate wizard. The
certificate displays in the
Microsoft OCS
certificate tab (because it is installed in the Local Computer store).
Select
Start > Programs > Administrative
Tools > Internet Information Services (IIS)
Manager.
Step 2
Expand the (local computer) tree on the right pane.
Step 3
Select
Default Web Site.
Step 4
Right-click to open the Propertiesdialog box.
Step 5
Select the
Certificate tab from the
Default Web Site Properties dialog box.
Step 6
If a certificate has already been selected, select
Delete Certificate to remove the selection
Step 7
Select
Certificate to launch the Certificate Wizard.
Step 8
Using the Certificate Wizard, select the certificate that was
installed for
Microsoft OCS.
Step 9
Launch the
Microsoft Office Communications Server 2007 application.
Step 10
In the right pane, select the server that represents the local
machine.
Step 11
Right-click on the server.
Step 12
Select
Properties > Front End
Properties.
Step 13
Select the
Certificate tab.
Step 14
Select on
Select Certificate.
Step 15
Find and select the installed certificate for
Microsoft OCS.
Note
If you are using Microsoft LCS, follow steps 1-7 above and then
open the
Microsoft Live Communications Server 2005
application. From the Administration Page, right-click on the
desired server to open the
Properties dialog box.Select the
Security tab, select
Select Certificate and select the newly
installed LCS certificate.
Configure a TLS route for IM and Presence on Microsoft OCS
Procedure
Step 1
Launch the
Microsoft Office Communications Server 2007 application.
Step 2
Right-click on
Microsoft OCS Server pool in
the right pane.
Step 3
Select
Properties > Front End
Properties.
Step 4
Select the
Routing
tab from the
Front End Server Properties dialog box.
Step 5
Select
Add.
Step 6
Perform the following actions to add a static route:
Enter the hostname/FQDN for
IM and Presence in the
Domain
field.
Note
This should match with Subject CN of the
IM and Presence certificate otherwise
Microsoft OCS will
not establish a TLS connection with
IM and Presence.
Select
TLS from the Transport menu.
Enter
5062 in the
Port field. The port number 5062 is the default
IM and Presence port where it listens for peer authentication TLS
connections.
Check
Replace host in request URI.
Select
OK.
Troubleshooting Tip
You can check Subject CN of an
IM and Presence certificate by selecting
Cisco Unified CM IM and Presence Operating System
Administration > Security > Certificate
Management, and selecting a certificate entry in
the certificate list.
IM and Presence only supports TLSv1 so you must configure
Microsoft OCS to use TLSv1.
This procedure describes how to configure FIPS-compliant algorithms on
Microsoft OCS to ensure that
Microsoft OCS sends TLSv1 with
TLS cipher TLS_RSA_WITH_3DES_EDE_CBC_SHA.
Procedure
Step 1
Select
Start > Administrative
Tools > Local Security Policy.
Step 2
Select
Security Settings in the console tree.
Step 3
Select
Local Policies.
Step 4
Select
Security Options.
Step 5
Double-click the FIPS security setting in the Details pane.
Step 6
Modify the security setting.
Step 7
Select
OK.
Step 8
Restart the Windows Server for the change to the FIBS security
setting to take effect.