Cisco CP-7911G-CH1 Administration Guide - Page 195

Troubleshooting Credential Settings, SUMMARY STEPS, DETAILED STEPS

Page 195 highlights

Configuring Secure SRST for SCCP and SIP How to Configure Secure Unified SRST Troubleshooting Credential Settings The following steps display credential settings or set debugging on the credential settings of the  Cisco Unified SRST Router. SUMMARY STEPS 1. show credentials 2. debug credentials DETAILED STEPS Step 1 Command or Action show credentials Example: Router# show credentials Step 2 Credentials IP: 10.1.1.22 Credentials PORT: 2445 Trustpoint: srstca debug credentials Example: Router# debug credentials Purpose Use the show credentials command to display the credential settings on the Cisco Unified SRST Router that are supplied to Cisco Unified Communications Manager for use during secure Cisco Unified SRST fallback. Use the debug credentials command to set debugging on the credential settings of the Cisco Unified SRST Router. Credentials server debugging is enabled Router# Sep 29 01:01:50.903: Credentials service: Start TLS Handshake 1 10.1.1.13 2187 Sep 29 01:01:50.903: Credentials service: TLS Handshake returns OPSSLReadWouldBlockErr Sep 29 01:01:51.903: Credentials service: TLS Handshake returns OPSSLReadWouldBlockErr Sep 29 01:01:52.907: Credentials service: TLS Handshake returns OPSSLReadWouldBlockErr Sep 29 01:01:53.927: Credentials service: TLS Handshake completes. Related Commands Use the following commands to show if a certificate cannot be found (you are missing a certificate that you are trying to authenticate) or to show that a particular certificate has matched (so you know what certificate the router used to authenticate a phone): • debug crypto pki messages • debug crypto pki transactions Importing Phone Certificate Files in PEM Format to the Secure SRST Router This task completes the tasks required for Cisco IP Unified Phones to authenticate secure SRST. OL-13143-04 Cisco Unified SCCP and SIP SRST System Administrator Guide 195

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

Configuring Secure SRST for SCCP and SIP
How to Configure Secure Unified SRST
195
Cisco Unified SCCP and SIP SRST System Administrator Guide
OL-13143-04
Troubleshooting Credential Settings
The following steps display credential settings or set debugging on the credential settings of the
Cisco Unified SRST Router.
SUMMARY STEPS
1.
show credentials
2.
debug credentials
DETAILED STEPS
Related Commands
Use the following commands to show if a certificate cannot be found (you are missing a certificate that
you are trying to authenticate) or to show that a particular certificate has matched (so you know what
certificate the router used to authenticate a phone):
debug crypto pki messages
debug crypto pki transactions
Importing Phone Certificate Files in PEM Format to the Secure SRST Router
This task completes the tasks required for Cisco IP Unified Phones to authenticate secure SRST.
Command or Action
Purpose
Step 1
show credentials
Example:
Router# show credentials
Credentials IP: 10.1.1.22
Credentials PORT: 2445
Trustpoint: srstca
Use the
show credentials
command to display the
credential settings on the Cisco Unified SRST
Router that are supplied to Cisco
Unified Communications Manager for use during
secure Cisco Unified SRST fallback.
Step 2
debug credentials
Example:
Router# debug credentials
Credentials server debugging is enabled
Router#
Sep 29 01:01:50.903: Credentials service: Start TLS
Handshake 1 10.1.1.13 2187
Sep 29 01:01:50.903: Credentials service: TLS
Handshake returns OPSSLReadWouldBlockErr
Sep 29 01:01:51.903: Credentials service: TLS
Handshake returns OPSSLReadWouldBlockErr
Sep 29 01:01:52.907: Credentials service: TLS
Handshake returns OPSSLReadWouldBlockErr
Sep 29 01:01:53.927: Credentials service: TLS
Handshake completes.
Use the
debug credentials
command to set
debugging on the credential settings of the Cisco
Unified SRST Router.