Configuring Registration Policy To Use An External Service - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Registration control
Configuring Registration Policy to use an
external service
To configure Registration Policy to refer all registration restriction policy decisions out to an external service:
1. Go to
Configuration > Registration >
2. Select a Restriction policy of Policy service.
3. Configure the fields as follows:
Field
Description
Protocol
The protocol used to connect to the policy
service.
The default is HTTPS.
Certificate
When connecting over HTTPS, this setting
verification
controls whether the certificate presented by
mode
the policy server is verified.
If On, for the VCS to connect to a policy server
over HTTPS, the VCS must have a root CA
certificate loaded that authorizes that server's
server certificate. Also the certificate's Subject
Common Name or Subject Alternative Name
must match one of the Server address fields
below.
HTTPS
Enable this option if you want to protect
certificate
certificate checking using CRLs and you have
revocation list
manually loaded CRL files, or you have
(CRL)
enabled automatic CRL updates.
checking
Server
Enter the IP address or Fully Qualified Domain
address 1 - 3
Name (FQDN) of the server hosting the service.
You can specify a port by appending :<port>
to the address.
Path
Enter the URL of the service on the server.
Status path
The Status path identifies the path from where
the VCS can obtain the status of the remote
service.
The default is status.
Username
The username used by the VCS to log in and
query the service.
Password
The password used by the VCS to log in and
query the service.
Cisco VCS Administrator Guide (X8.1.1)

Configuring Registration Policy to use an external service

Configuration.
Usage tips
The VCS automatically supports HTTP to
HTTPS redirection when communicating
with the policy service server.
The VCS's root CA certificates are loaded
via
> Trusted CA
Go to
certificates > CRL management
configure how the VCS uploads CRL files.
If an FQDN is specified, ensure that the
VCS has an appropriate DNS
configuration that allows the FQDN to be
resolved.
For resiliency, up to three server
addresses can be supplied.
The policy server must supply return status
information, see
resiliency
The maximum plaintext length is 30
characters (which is subsequently
encrypted).
(Maintenance > Security certificates
certificate).
Maintenance > Security
Policy server status and
[p.338].
to
Page 99 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents