# Troubleshooting phone trust and ITL failures in Unified CM

Canonical: https://warmtransfer.net/knowledge/cucm-itl-trust-troubleshooting

Last verified: 2026-10-01

Security By Default (SBD) provides supported Cisco IP phones with default authentication of TFTP files, optional configuration file encryption, and certificate verification without requiring extra configuration[^48]. Cisco's Security By Default and ITL technote applies to Unified Communications Manager 8.0 and later, and ITL-based Security By Default does not exist on earlier releases[^47].

## How trust and the ITL operate

The Initial Trust List (ITL) file is created automatically when the TFTP service is activated during cluster installation, requiring no administrator action to create it[^14]. The ITL file contains the ITLRecovery certificate, the CallManager certificate of the TFTP server, all Trust Verification Service (TVS) certificates in the cluster, and the CAPF certificate[^15]. Since Unified CM 8.0, the CallManager.pem certificate serves as the TFTP certificate, and TFTP configuration files are signed with its private key[^52].

On boot, an IP phone requests the CTL file, then the ITL file[^39]. Once these verify, the phone requests signed configuration files with the `.sgn` extension[^39].

Network services and ports involved in phone trust include:
- TVS acts as a remote certificate trust store so phones do not need to store every trusted certificate, allowing phones to forward certificates they cannot verify against their local CTL or ITL[^56]. TVS runs on every Unified CM server where the CallManager service is active[^54]. Phones reach TVS over TCP port 2445[^55].
- Phones download firmware and configuration files from Unified CM TFTP over HTTP on TCP port 6970 as well as TFTP on UDP port 69[^50]. Secure configuration files are downloaded over the HTTPS interface to Unified CM TFTP using TCP ports 6971 and 6972[^51].
- CAPF listens on TCP port 3804 to issue Locally Significant Certificates to IP phones[^8].

## Diagnosing ITL and configuration failures

In the field, phones with stale or mismatched ITL or security settings are reported as failing to move to another cluster, failing to download updated TFTP configuration files, and failing HTTPS-based authentication URLs[^18]. 

On the Cisco IP Phone 8800 series, if the ITL authenticates but other configuration files do not, the documented cause is that the configuration file is not signed by the matching certificate in the phone's trust list[^37]. TFTP authorization on the 8800 series fails when the phone's TFTP address is not in the CTL file, such as after a new CTL adds a TFTP server the phone's existing CTL lacks[^38].

The CLI command `show itl` displays ITL contents, checksums, and which certificate signed the ITL file[^49].

## Certificate regeneration and mixed-mode considerations

When renewing certificates across a cluster, administrators must observe specific sequencing rules:
- CallManager, TVS, Tomcat, and IPsec certificates are regenerated on the publisher first and then on each subscriber in turn[^43]. CAPF (14+) and ITLRecovery (12.5+) are regenerated on the publisher only[^43].
- Do not regenerate the CallManager and TVS certificates at the same time, because if both change together, phones cannot download new files until the ITL is deleted manually on each phone[^35]. The regeneration technote limits the CallManager-plus-TVS warning to versions 8.x through 11.5, or to clusters where the ITL is signed by the CallManager certificate[^10].
- After regenerating the CallManager certificate, restart the CallManager, CTIManager, Trust Verification, and TFTP services, and reset all phones[^41]. If SSO or OAuth is enabled, restart HAProxy as well[^41].
- After regenerating the TVS certificate, restart the Trust Verification Service and TFTP service on all nodes, and reset all phones[^44].
- The Release 15 guide states that phones reset automatically to receive the updated ITL after the CallManager, CAPF, or TVS certificate is regenerated or renewed[^40].
- Endpoints that already possessed a bad ITL prior to regeneration will not re-register afterwards, and Cisco's practice is to delete the ITL or CTL on those phones after the process once other devices register[^1].

On mixed-mode clusters, `utils ctl` commands (`set-cluster mixed-mode`, `set-cluster non-secure-mode`, and `update CTLFile`) run only on the publisher, and encrypted and authenticated phones must be reset for CTL updates to take effect[^58]. On a mixed-mode cluster, run `utils ctl update CTLFile` on the publisher after regenerating CAPF, CallManager, or ITLRecovery and before restarting services[^33]. If the ITLRecovery certificate has changed and endpoints are locked out, running `utils ctl reset localkey` on the publisher regenerates the CTL file signed with the CallManager key (secondary SAST); run `utils ctl update CTLFile` again afterwards[^12].

## ITL recovery and bulk reset procedures

The ITLRecovery key and certificate were introduced in Unified CM 10.0(1) to recover phone trust without requiring deletion of the ITL on each individual phone[^26]. Cisco extended ITLRecovery certificate validity from 5 years to 20 years[^31]. However, an upgrade alone keeps an existing ITLRecovery certificate at 5-year validity; the 20-year validity applies only after a fresh install or after the ITLRecovery certificate is regenerated[^30]. Cisco advises against regenerating the ITLRecovery certificate frequently because phones trust it for a long period[^27].

A bulk ITL reset restores trust only on phones whose current ITL already contains the ITLRecovery entry; phones holding an older ITL lacking that entry cannot be recovered this way[^20]. The ITL reset feature cannot be used to move phones between clusters[^21].

The bulk ITL reset procedure consists of running `utils itl reset localkey` or `remotekey`, confirming with `show itl`, then navigating to System > Enterprise Parameters in Unified CM Administration and clicking Reset so devices restart and fetch the new ITL[^22]. Running `utils itl reset localkey` re-signs the cluster ITL with the ITLRecovery private key from the `ITLRecovery.p12` file stored on the publisher[^19]. Running `utils itl reset remotekey` performs the same re-signing with an `ITLRecovery.p12` retrieved from an external SFTP server, which is used when the local key is not on the publisher[^23].

## Cluster rollbacks and migrations

Setting the enterprise parameter "Prepare Cluster for Rollback to Pre 8.0" makes the cluster serve a signed ITL with blank function entries, which temporarily disables authenticated configuration, encryption, and HTTPS verification on phones[^46]. Cisco does not recommend leaving a cluster with this parameter enabled[^45].

For cluster migrations, bulk certificate export, consolidate, and import functions are located under Cisco Unified OS Administration > Security > Bulk Certificate Management[^4]. This management requires an SFTP server reachable from both clusters to store and consolidate exported PKCS12 files[^7]. Bulk Certificate Export only functions for phone migration if both the old and new clusters remain online with network connectivity during the migration[^2]. Before a bulk certificate migration, Prepare Cluster for Rollback to Pre 8.0 must be False on the source cluster[^5]. The bulk certificate migration order is to export the destination cluster's certificates to SFTP, export the source cluster's to the same location, consolidate once on one cluster, import into both clusters, then point the phones at the destination TFTP and reset them[^6].

For Extension Mobility Cross Cluster (EMCC) to keep working, the bulk import must also bring in an additional ITLRecovery certificate on both the visiting and home clusters[^13].

## Manual ITL deletion

Cisco states that an ITL should be deleted on a phone only when all 4 conditions hold: the phone's ITL signature differs from the CUCM ITL, the TVS signature in the ITL differs from the certificate presented by TVS, downloads show "Verification Failed", and no backup of the old TFTP private key exists[^16]. The SBD technote notes that Cisco provides no method to delete all ITLs from phones remotely, requiring deletion to be performed on each phone[^34].

In the field, practitioners delete the ITL on Cisco 8841, 8851, and 8861 phones by navigating to Applications > Admin Settings > Reset Settings > Security Settings and confirming with Reset[^36]. On the Cisco 8831, the menu sequence used in the field is Apps > Admin Settings > Reset Settings > Security[^36].

## See also

See also [Unified CM certificate renewal](https://warmtransfer.net/knowledge/cucm-certificate-renewal).
See also [Troubleshooting Cisco IP phone registration](https://warmtransfer.net/knowledge/cisco-phone-registration-troubleshooting).
See also [Enabling mixed mode and encrypted calling in Unified CM](https://warmtransfer.net/knowledge/cucm-secure-calling-setup).

## Applicability

Applies to: Cisco Unified Communications Manager and Cisco IP Phone 8800 Series. Deployments: on-premises. Sources checked 2026-10-01. Cisco's Security By Default and ITL technote applies to Unified Communications Manager 8.0 and later[^47]. The ITLRecovery key and certificate were introduced in Unified CM 10.0(1)[^26]. Cisco extended ITLRecovery certificate validity from 5 years to 20 years[^31]. The CallManager-plus-TVS warning is limited to versions 8.x through 11.5, or to clusters where the ITL is signed by the CallManager certificate[^10].

## What remains uncertain

ITL and security reset menu paths on Cisco 9800 and 7800 phones are not covered by the sources below.
Whether simultaneous CallManager and TVS regeneration is safe on 12.5 and later is not covered by the sources below.
Phone migration from CUCM to Webex Calling Dedicated Instance and ITL handling is not covered by the sources below.
The release in which ITL signing moved to ITLRecovery is not covered by the sources below.
ITL relevance when converting enterprise phones to MPP for Webex Calling is not covered by the sources below.
ITL and TVS behaviour for MRA phones through Expressway is not covered by the sources below.
How ECDSA and multi-server SAN TVS certificates appear in the ITL is not covered by the sources below.
The exact utils itl reset CLI reference entry for Release 15 is not covered by the sources below.

## Sources

[^1]: Endpoints that already had a bad ITL before regeneration will not re-register afterwards. Cisco's practice is to delete the ITL/CTL on those phones after the process, once the other devices have registered. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), ITL/CTL deletion guidance section. Checked 2026-10-01.
[^2]: Bulk Certificate Export only works for phone migration if both the old and new clusters are online with network connectivity while the phones migrate. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_certificates.html), Certificates > Bulk certificate export section. Checked 2026-10-01.
[^3]: After a bulk certificate import, a migrating phone asks its home (source) cluster's TVS to validate the destination cluster's certificates before it accepts the destination ITL. Source: [Manage Bulk Certificates between CUCM Clusters for Phone Migration](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215539-procedure-for-bulk-certificate-managemen.html), Verify / phone migration explanation. Checked 2026-10-01.
[^4]: Bulk certificate export, consolidate and import are done under Cisco Unified OS Administration > Security > Bulk Certificate Management. Source: [Manage Bulk Certificates between CUCM Clusters for Phone Migration](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215539-procedure-for-bulk-certificate-managemen.html), Configure section. Checked 2026-10-01.
[^5]: Before a bulk certificate migration, Prepare Cluster for Rollback to Pre 8.0 must be False on the source cluster. Source: [Manage Bulk Certificates between CUCM Clusters for Phone Migration](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215539-procedure-for-bulk-certificate-managemen.html), Prerequisites / Requirements section. Checked 2026-10-01.
[^6]: Bulk certificate migration order: export the destination cluster's certificates to SFTP, export the source cluster's to the same location, consolidate once on one cluster, import into both clusters, then point the phones at the destination TFTP and reset them. Source: [Manage Bulk Certificates between CUCM Clusters for Phone Migration](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215539-procedure-for-bulk-certificate-managemen.html), Configure section (numbered procedure). Checked 2026-10-01.
[^7]: Bulk certificate management for phone migration needs an SFTP server reachable from both clusters, where the exported PKCS12 files are stored and consolidated. Source: [Manage Bulk Certificates between CUCM Clusters for Phone Migration](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215539-procedure-for-bulk-certificate-managemen.html), Prerequisites / Requirements section. Checked 2026-10-01.
[^8]: CAPF listens on TCP 3804 to issue Locally Significant Certificates to IP phones. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Cisco Unified Communications Manager TCP and UDP Port Usage](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_tcp-and-udp-port-usage-12-0.html), Table: Signaling, Media, and Other Communication Between Phones and Cisco Unified Communications Manager, row TCP 3804. Checked 2026-10-01.
[^9]: With centralized TFTP, phones that receive an ITL from the central TFTP server do not trust files from a remote cluster's TFTP server, because the signatures do not match. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Centralized TFTP section. Checked 2026-10-01.
[^10]: The regeneration technote limits the CallManager-plus-TVS warning to versions 8.x through 11.5, or to clusters where the ITL is signed by the CallManager certificate. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), Prerequisites / CallManager and TVS timing note. Checked 2026-10-01.
[^11]: Inference: on releases after 11.5 where show itl reports the ITL is signed by the ITLRecovery certificate, regenerating CallManager and TVS together is probably not the unrecoverable case described for older releases. Cisco does not state this as a recommendation (inferred). Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), Prerequisites / CallManager and TVS timing note (scope wording). Checked 2026-10-01.
[^12]: utils ctl reset localkey, run on the publisher, regenerates the CTL file signed with the CallManager key (secondary SAST) for when the ITLRecovery certificate has changed and endpoints are locked out. Run utils ctl update CTLFile again afterwards. Source: [Command Line Interface Reference Guide for Cisco Unified Communications Solutions, Release 15 and SUs - Utils Commands](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/cli_ref/15/cucm_b_cli_reference_guide_release_15/cucm_b_cli_reference_guide_release_1401_chapter_01001.html), utils ctl reset localkey command entry. Checked 2026-10-01.
[^13]: For Extension Mobility Cross Cluster to keep working, the bulk import must also bring in an additional ITLRecovery certificate on both the visiting and home clusters. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_certificates.html), Certificates > Bulk certificate export section (EMCC note). Checked 2026-10-01.
[^14]: The Initial Trust List (ITL) file is created automatically when the TFTP service is activated during cluster installation; no administrator action is needed to create it. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List. Checked 2026-10-01.
[^15]: The ITL file holds the ITLRecovery certificate, the CallManager certificate of the TFTP server, all TVS certificates in the cluster, and the CAPF certificate. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List (ITL contents list). Checked 2026-10-01.
[^16]: Cisco says to delete a phone's ITL only when all four hold: the phone's ITL signature differs from the CUCM ITL, the TVS signature in the ITL differs from the certificate TVS presents, downloads show Verification Failed, and no backup of the old TFTP private key exists. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Troubleshoot section (when to delete the ITL). Checked 2026-10-01.
[^17]: To diagnose an ITL signature mismatch, compare the ITL MD5 checksum shown on the phone under Settings > Security Configuration > Trust List with the ITL on the TFTP server, and check that the TVS certificate serial number matches the ITL record. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Troubleshoot section (ITL signature mismatch). Checked 2026-10-01.
[^18]: Field pattern: phones with stale or mismatched ITL or security settings are reported as failing to move to another cluster, failing to download updated TFTP configuration files, and failing HTTPS-based authentication URLs (field report). Source: [Delete ITL File/Reset Security Settings on Cisco 8800 IP Phones](https://kb.variphy.com/knowledge-base/delete-itl-file-reset-security-settings-on-cisco-8800-ip-phones/), Introductory symptoms paragraph. Checked 2026-10-01.
[^19]: utils itl reset localkey re-signs the cluster ITL with the ITLRecovery private key from the ITLRecovery.p12 file stored on the publisher. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Bulk ITL reset section (localkey). Checked 2026-10-01.
[^20]: A bulk ITL reset only restores trust on phones whose current ITL already contains the ITLRecovery entry. Phones holding an older ITL without that entry cannot be recovered this way. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Bulk ITL reset section (prerequisite). Checked 2026-10-01.
[^21]: The ITL reset feature cannot be used to move phones between clusters. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Limitations section. Checked 2026-10-01.
[^22]: Bulk ITL reset procedure: run utils itl reset localkey or remotekey, confirm with show itl, then go to System > Enterprise Parameters in Unified CM Administration and click Reset so devices restart and fetch the new ITL. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Perform Bulk Reset of ITL File. Checked 2026-10-01.
[^23]: utils itl reset remotekey does the same re-signing with an ITLRecovery.p12 retrieved from an external SFTP server. It is used when the local key is not on the publisher. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Bulk ITL reset section (remotekey). Checked 2026-10-01.
[^24]: The Release 15 security guide says the ITLRecovery certificate signs the ITL file (disputed). Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List (ITLRecovery Certificate bullet). Checked 2026-10-01.
[^25]: The Release 15 security guide also says the ITL file is signed with the TFTP server's private key, which is the CallManager certificate key (disputed). Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List (introductory paragraph). Checked 2026-10-01.
[^26]: The ITLRecovery key and certificate were introduced in Unified CM 10.0(1) to recover phone trust without deleting the ITL on each phone. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Introduction / ITLRecovery section. Checked 2026-10-01.
[^27]: Cisco advises against regenerating the ITLRecovery certificate frequently, because phones trust it for a long period. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_certificates.html), Certificates > ITLRecovery certificate note. Checked 2026-10-01.
[^28]: The ITLRecovery key can be copied to an SFTP server with the CLI command file get tftp ITLRecovery.p12. DRS backup alone does not clear the daily RTMT reminder to back it up. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Backup of the ITLRecovery key section. Checked 2026-10-01.
[^29]: The ITLRecovery certificate subject is CN=ITLRECOVERY_<publisher hostname>, and the entry stays the same across hostname and DNS changes so phones keep trusting it. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), ITLRecovery certificate section. Checked 2026-10-01.
[^30]: An upgrade alone keeps an existing ITLRecovery certificate at 5-year validity. The 20-year validity applies only after a fresh install or after the ITLRecovery certificate is regenerated. Source: [Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/12_5_1SU3/cucm_b_security_guide_1251SU3/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List (ITLRecovery validity note). Checked 2026-10-01.
[^31]: Cisco extended ITLRecovery certificate validity from 5 years to 20 years. Source: [Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/12_5_1SU3/cucm_b_security_guide_1251SU3/cucm_m_default-security-setup_su2_reorg.html), Default Security > Initial Trust List (ITLRecovery validity note). Checked 2026-10-01.
[^32]: In Unified CM 10.0(1) the ITLRecovery certificate had a five-year validity and had to be regenerated when it expired. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), ITLRecovery certificate section (validity). Checked 2026-10-01.
[^33]: On a mixed-mode cluster, run utils ctl update CTLFile on the publisher after regenerating CAPF, CallManager or ITLRecovery and before restarting services. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), Mixed-mode requirement note. Checked 2026-10-01.
[^34]: The SBD technote states that Cisco provides no method to delete all ITLs from phones remotely; deletion is done on each phone. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Troubleshoot section (deleting the ITL). Checked 2026-10-01.
[^35]: Do not regenerate the CallManager and TVS certificates at the same time. If both change together, phones cannot download new files until the ITL is deleted manually on each phone. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Regenerate certificates section. Checked 2026-10-01.
[^36]: Field pattern: on Cisco 8841, 8851 and 8861 phones, practitioners delete the ITL via Applications > Admin Settings > Reset Settings > Security Settings and confirm with Reset. The 8831 uses Apps > Admin Settings > Reset Settings > Security (field report). Source: [Delete ITL File/Reset Security Settings on Cisco 8800 IP Phones](https://kb.variphy.com/knowledge-base/delete-itl-file-reset-security-settings-on-cisco-8800-ip-phones/), Per-model sections (8831; 8841; 8851/8861). Checked 2026-10-01.
[^37]: On Cisco IP Phone 8800 series, if the ITL authenticates but other configuration files do not, the documented cause is that the configuration file is not signed by the matching certificate in the phone's trust list. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01110.html), Cisco IP Phone Security Problems > CTL File Problems > ITL File Authenticates but Other Configuration Files Do Not Authenticate. Checked 2026-10-01.
[^38]: On Cisco IP Phone 8800 series, TFTP authorization fails when the phone's TFTP address is not in the CTL file, for example after a new CTL adds a TFTP server the phone's existing CTL lacks. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01110.html), Cisco IP Phone Security Problems > CTL File Problems > TFTP Authorization Fails. Checked 2026-10-01.
[^39]: On boot a phone requests the CTL file, then the ITL file. Once these verify, it requests signed configuration files with the .sgn extension. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Phone download / ITL verification section (phone console log walkthrough). Checked 2026-10-01.
[^40]: The Release 15 guide says phones reset automatically to receive the updated ITL after the CallManager, CAPF or TVS certificate is regenerated or renewed. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_certificates.html), Certificates > certificate regeneration section. Checked 2026-10-01.
[^41]: After regenerating the CallManager certificate, restart the CallManager, CTIManager, Trust Verification and TFTP services and reset all phones. Restart HAProxy as well if SSO or OAuth is enabled. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), CallManager certificate section (steps). Checked 2026-10-01.
[^42]: Before regenerating certificates, all endpoints should be powered on and registered so they can pick up the updated ITL. Phones offline during the change may need the ITL removed manually afterwards. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), Prerequisites section. Checked 2026-10-01.
[^43]: Regenerate CallManager, TVS, Tomcat and IPsec certificates on the publisher first and then on each subscriber in turn. CAPF (14+) and ITLRecovery (12.5+) are regenerated on the publisher only. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), Per-certificate regeneration sections and procedural order note. Checked 2026-10-01.
[^44]: After regenerating the TVS certificate, restart the Trust Verification Service and TFTP service on all nodes and reset all phones. Source: [Regenerate Certificates In Unified Communications Manager](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html), TVS certificate section (steps). Checked 2026-10-01.
[^45]: Cisco does not recommend leaving a cluster with Prepare Cluster for Rollback to Pre 8.0 enabled. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Rollback / Prepare Cluster for Rollback to Pre 8.0 section. Checked 2026-10-01.
[^46]: Setting the Prepare Cluster for Rollback to Pre 8.0 enterprise parameter makes the cluster serve a signed ITL with blank function entries. This temporarily disables authenticated configuration, encryption and HTTPS verification on phones. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Rollback / Prepare Cluster for Rollback to Pre 8.0 section. Checked 2026-10-01.
[^47]: Cisco's Security By Default and ITL technote applies to Unified Communications Manager 8.0 and later; ITL-based Security By Default does not exist on earlier releases. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Introduction / Components Used. Checked 2026-10-01.
[^48]: Security By Default gives supported Cisco IP phones default authentication of TFTP files, optional encryption of configuration files, and certificate verification without extra configuration. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Security By Default. Checked 2026-10-01.
[^49]: The CLI command show itl displays the ITL contents and checksums and shows which certificate signed the ITL file. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), Verify section (show itl output). Checked 2026-10-01.
[^50]: Phones download firmware and configuration files from Unified CM TFTP over HTTP on TCP 6970 as well as TFTP on UDP 69. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Cisco Unified Communications Manager TCP and UDP Port Usage](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_tcp-and-udp-port-usage-12-0.html), Table: Signaling, Media, and Other Communication Between Phones and Cisco Unified Communications Manager, rows UDP 69 and TCP 6970. Checked 2026-10-01.
[^51]: TCP 6971 and 6972 are the HTTPS interface to Unified CM TFTP. Phones use them to download secure configuration files. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Cisco Unified Communications Manager TCP and UDP Port Usage](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_tcp-and-udp-port-usage-12-0.html), Table: Signaling, Media, and Other Communication Between Phones and Cisco Unified Communications Manager, row TCP 6971, 6972. Checked 2026-10-01.
[^52]: Since Unified CM 8.0 the CallManager.pem certificate serves as the TFTP certificate, and TFTP configuration files are signed with its private key. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Background / ITL file section (CallManager.pem description). Checked 2026-10-01.
[^53]: In the Release 15 certificate model the TVS certificate supports multi-server SAN certificates, and from Release 14 CallManager and CallManager-ECDSA certificates support multi-server SAN self-signed certificates. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_certificates.html), Certificates > certificate types list and multi-server SAN note. Checked 2026-10-01.
[^54]: TVS runs on every Unified CM server where the CallManager service is active. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), TVS section. Checked 2026-10-01.
[^55]: Phones reach the Trust Verification Service on Unified CM over TCP port 2445. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Cisco Unified Communications Manager TCP and UDP Port Usage](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_tcp-and-udp-port-usage-12-0.html), Table: Signaling, Media, and Other Communication Between Phones and Cisco Unified Communications Manager, row TCP 2445. Checked 2026-10-01.
[^56]: The Trust Verification Service (TVS) acts as a remote certificate trust store. Phones send it certificates they cannot verify from their local CTL or ITL, so they do not need to store every trusted certificate. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html), Default Security > Trust Verification Service. Checked 2026-10-01.
[^57]: If a phone meets a certificate that is not in its CTL or ITL and cannot reach TVS, the certificate cannot be verified and the HTTPS connection fails. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), TVS section (phone verification of unknown certificates). Checked 2026-10-01.
[^58]: utils ctl commands (set-cluster mixed-mode, set-cluster non-secure-mode, update CTLFile) run only on the publisher, and encrypted and authenticated phones must be reset for CTL updates to take effect. Source: [Command Line Interface Reference Guide for Cisco Unified Communications Solutions, Release 15 and SUs - Utils Commands](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/cli_ref/15/cucm_b_cli_reference_guide_release_15/cucm_b_cli_reference_guide_release_1401_chapter_01001.html), utils ctl command entry (requirements and usage guidelines). Checked 2026-10-01.
