MrKernel Network

April 18, 2008

Office Communicator Phone Edition (OCPE) aka Tanjay - Certificate install

Filed under: Microsoft, VoIP — justin.berg @ 6:44 pm

UPDATE: http://www.mrkernel.net/?p=27#more-27

I got a hold of a few OCPE devices. Both the Polycom CX700 http://www.polycom.com/usa/en/products/voice/desktop/cx/communicator_cx700.html and the LG-Nortel 8540 http://www.nortel.com/8540. As anyone who has tried to connect them to Office Communication Server (OCS) 2007 knows, the first thing you must do is get the CA certificate on the phones. Being that they are RTM firmware the official ways of doing this are http://blogs.technet.com/jenstr/archive/2007/11/17/how-to-make-the-root-ca-certificate-available-for-office-communicator-2007-phone-edition.aspx. This works fairly slick except, in my experience, when the phone is not on the same subnet of a domain controller. When the OCPE is factory defaults and on different subnet from a domain controller it is unable to download the certificate. The error I get is “Cannot download certificate because domain is not accessible.”

Doing a packet trace I see that the OCPE does a broadcast for the domain in attempt to find it, it does not use DNS to find the domain. If I put the OCPE on the same subnet as a Domain Controller it downloads the certificate, and once that is done I am able to move it to another subnet. Great I thought it sucks that I can’t figure out how to deploy a phone on a non Domain Controller subnet but at least I have a workaround. I have since then deployed an OCPE Update Server. Guess what, when a phone gets upgraded it loses its CA Certificate. The login and PIN/Fingerprint are retained put not the Certificate. So the phone is no longer able to register. So what could I do to get this to work? Well, back in Windows NT4.0 when you needed to access a Domain Controller on a different subnet what did you use? Well WINS of course. But surely a newly engineered device in 2008 would not be able to utilize WINS. Guess what it does, I fired up a WINS service on one of my boxes, added the ip address to the DHCP scope of the OCPE and vola, certificate downloaded. So this really bugs me, I haven’t used WINS since before 2000, does Microsoft honestly expect its customers to deploy a WINS infrastructure just for an OCPE  deployment? If anyone else has had different or similar experience with the OCPE and different subnets please let me know. I will post a solution if I find one.

5 Comments »

  1. Thank you so much for this post. This was exacly our problem and implementing the WINS server worked for us as well… I’m still having a hard time swallowing how 2008 technology relies on a server component that I haven’t used in over 5 years… :(

    Comment by Chuck Jones — July 13, 2008 @ 3:07 pm

  2. Hello! Please e-mail me your contacts. I have a question zachary@complective.ru” rel=”nofollow”>……

    Thanks!…

    Trackback by Frankie — June 11, 2010 @ 1:04 pm

  3. Medicamentspot.com International Legal RX Medications. Special Internet Prices (up to 40% off average US price). NO PRIOR PRESCRIPTION REQUIRED!…

    Combivir@buy.online” rel=”nofollow”>.…

    Trackback by CAMERON — June 24, 2010 @ 5:47 am


  4. Medicamentspot.com. Canadian Health&Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. High quality drugs. Buy drugs online

    Buy:Zyban.Prevacid.Retin-A.Petcam (Metacam) Oral Suspension.Accutane.Arimidex.Actos.Mega Hoodia.Synthroid.Nexium.Zovirax.Prednisolone.100% Pure Okinawan Coral Calcium.Human Growth Hormone.Lumigan.Valtrex….

    Trackback by CHARLES — July 21, 2010 @ 2:33 am

  5. eBay. http://ppc0rackf.05KIAPARTS.US/tag/Propane+eBay.+add+on/ : add…

    on…

    Trackback by on — August 29, 2010 @ 9:41 pm

RSS feed for comments on this post. TrackBack URL

Leave a comment

Powered by WordPress