This document answers questions related to the Elliptic Curve Digital Signature Algorithm (ECDSA) certificates that works with the Cisco IM and Presence (IM&P) appliance.
Cisco recommends that you have knowledge of these topics:
The information in this document is based on these software and hardware versions:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
In reference to the enterprise parameter Transport Layer Security (TLS) ciphers, the default selection is All Ciphers RSA Preferred. So in reference to parameter TLS ciphers, the following questions were raised with the IM&P Engineering team.
Note: All questions are answered and verified by the IM&P Engineering Team.
Yes. This parameter is only for CUCM SIP/CTI interface. RSA ciphers is given preference over ECDSA.
It is for giving preference to RSA ciphers but it has ECDSA ciphers as well, but when client initiates a connection it sends RSA ciphers above ECDSA.
Yes. This parameter comes into the picture only when CUCM acts as a client. The preference is given to order in which the client initiates the connection. If the client initiates a connection with ECDSA ciphers on the top, then the connection happens with ECDSA. If not then then RSA is given preference.
Yes. When server acts as a client it sends the cipher in the order it is mentioned in the previous questions.
Yes. There is a help option as soon as you select the TLS Ciphers link on the enterprise parameters page which states the list of the ciphers supported.
Yes.
Yes.
All Ciphers RSA Preferred
Includes Ciphers in the following order:
TLS_ECDHE_RSA with AES256_GCM_SHA384
TLS_ECDHE_ECDSA with AES256_GCM_SHA384
TLS_ECDHE_RSA with AES128_GCM_SHA256
TLS_ECDHE_ECDSA with AES128_GCM_SHA256
TLS_RSA with AES_128_CBC_SHA1
Yes.
Yes.
No. There is a feature enhancement for XMPP, but it is not yet implemented.