Configuration · guide

Enabling mixed mode and encrypted calling in Unified CM

Cisco Unified CM

Verified 2026-10-01 · 67 sources · tier 2

For Unified CM administrators enabling tokenless mixed mode and secure signaling and media on phones and trunks.

Non-secure mode is the default security mode when Unified CM is first installed, providing no secure signaling or media services 21. In mixed mode, Unified CM uses TLS for signaling and SRTP for media 18.

Before you start

  • Mixed mode requires Unified CM to be registered with Cisco Smart Software Manager or a Smart Software Manager satellite with export-controlled functionality enabled 25.
  • Before setting mixed mode, the Certificate Authority Proxy Function (CAPF) service and the Certificate Trust List (CTL) Provider service must be enabled on the publisher 24.
  • The utils ctl commands are not allowed while an upgrade is in progress 60.
  • The utils ctl command must be run on the publisher; it is disabled on all other nodes 61.
  • As of Unified CM 14SU3, the Cisco CTL Provider service no longer supports CTL (USB) tokens, and tokenless is the default supported method 48.
  • Tokenless CTL, available from Unified CM 10.0(1), enables encryption of IP phone signaling and media without hardware USB eTokens 46.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

What security state is the cluster in today?
What protection should phones get?
Should SIP trunks also be secured?

Three questions. One permanent page you can send to your manager.

Step 1 Check prerequisites and export the ITLRecovery key

Do

Export the ITLRecovery key pair for disaster recovery with the CLI command file get tftp ITLRecovery.p12 to an SFTP server 16.

Verify

Suggested check: verify that the Smart Software Manager registration confirms export-controlled functionality is enabled, and confirm the ITLRecovery.p12 file exists on the SFTP destination.

Step 2 Activate CAPF and CTL Provider services on the publisher

Do

On the publisher, activate the Cisco Certificate Authority Proxy Function service from Cisco Unified Serviceability > Tools > Service Activation 2. Activate the Cisco CTL Provider service as well 24. If using Online CA mode, also activate the Cisco Certificate Enrollment Service 2. CAPF runs in one of 3 modes: Cisco Authority Proxy Function (the default, where CAPF signs LSCs itself), Online CA (an external CA signs automatically), or Offline CA (CSRs are downloaded, signed externally, and uploaded manually) 5.

Verify

Suggested check: in Service Activation, verify that the Certificate Authority Proxy Function and CTL Provider services display an Activated status.

Rollback

Suggested rollback: deactivate the Certificate Authority Proxy Function and CTL Provider services in Service Activation before mixed mode is enabled.

Step 3 Put the cluster into tokenless mixed mode

Non-secure mode

Do

On the publisher CLI, run utils ctl set-cluster mixed-mode to update the CTL file and set the cluster to mixed mode 7 61.

Verify

Confirm mixed mode when the Cluster Security Mode field in the Security Parameters pane of System > Enterprise Parameters shows the value 1 63. Alternatively, run the CLI query run sql select paramname,paramvalue from processconfig where paramname='ClusterSecurityMode', which returns 1 when the cluster is in mixed mode 44. View the contents and checksum of the CTL file using show ctl 42.

Rollback

Return a tokenless mixed-mode cluster to non-secure mode by running utils ctl set-cluster non-secure-mode on the publisher 19 61.

Mixed mode using USB eTokens

Do

To move from a USB-token CTL to tokenless, endpoints must first download a token-generated CTL file uploaded on Unified CM 12.0(1) or later; only after that download can the cluster switch to tokenless with utils ctl update CTLFile on the publisher 45 61.

Verify

Run show ctl on the publisher to display the updated CTL file contents and checksum 42. Confirm that the Cluster Security Mode field in System > Enterprise Parameters shows 1 63.

Rollback

Suggested rollback: because support for USB tokens has ended, return the cluster to non-secure mode using utils ctl set-cluster non-secure-mode rather than rolling back to USB tokens.

Step 4 Restart cluster services and reset IP phones

Do

Restart the TFTP and Cisco CallManager services on all nodes in the cluster 39. Restart all IP phones so they obtain the CTL file from the Unified CM TFTP service 38. Encrypted and Authenticated phones must be reset after every utils ctl CTL update for the update to take effect 62 64.

Verify

Check the CTL file on a phone under Settings > Security Configuration > Trust List > CTL File and compare its checksum with the output of show ctl 23.

Step 5 Issue Locally Significant Certificates via CAPF

Do

CAPF issues Locally Significant Certificates (LSCs) to supported Cisco IP phones, authenticates phones in mixed mode, upgrades existing LSCs, and retrieves phone certificates for troubleshooting 4. CAPF listens on TCP 3804 to issue Locally Significant Certificates to IP phones 65. Set the per-phone Certificate Operation field to Install/Upgrade to deploy an LSC 3. The phone security profile's CAPF Authentication Mode options include By Null String, By Existing Certificate (Precedence to LSC), and By Existing Certificate (Precedence to MIC) 28.

Verify

Check LSC status on the Phone Configuration page, in CAPF reports, or from Find and List Phones 6.

Rollback

Set the Certificate Operation field to Delete to remove the LSC 3.

Step 6 Create or configure the phone security profile

Encrypted (TLS signaling and SRTP media)

Do

Create phone security profiles in Unified CM Administration under System > Security > Phone Security Profile using Add New or by copying an existing profile 30. Set Device Security Mode to Encrypted, which provides integrity, authentication, and encryption for the phone 29. Checking TFTP Encrypted Config in the profile makes Unified CM encrypt the phone's downloads from the TFTP server 31.

Verify

Confirm that the Device Security Mode displays Encrypted, and verify that TLS is set as the transport type automatically 32.

Rollback

Suggested rollback: delete the profile, or leave it unassigned to endpoints.

Authenticated (TLS signaling with integrity and authentication only)

Do

Create phone security profiles in Unified CM Administration under System > Security > Phone Security Profile using Add New or by copying an existing profile 30. Set Device Security Mode to Authenticated, which provides integrity and authentication using a TLS connection with NULL/SHA for signaling 27.

Verify

Confirm that the Device Security Mode displays Authenticated, and verify that TLS is set as the transport type automatically 32.

Rollback

Suggested rollback: delete the profile, or leave it unassigned to endpoints.

Step 7 Apply the security profile to phones

Do

In Device > Phone, apply the profile by selecting it in Device Security Profile, clicking Save, and then clicking Apply Config; then reset the phone for the change to take effect 26.

Verify

Suggested check: verify that the phone re-registers successfully after the reset.

Rollback

Re-select the previous non-secure security profile in Device Security Profile, click Save, click Apply Config, and reset the phone 26.

Step 8 Verify call security on phones

Encrypted (TLS signaling and SRTP media)

Do

Secure tones play only on phones configured as protected devices: 3 long beeps indicate a secure call and 6 short beeps a non-secure call 41.

Verify

Suggested check: place a call between phones configured with the Encrypted profile. The lock icon on a phone means both call signaling (TLS) and call media (SRTP) are encrypted 12. A call registers as secure only if every device in the call registers as secure; 1 nonsecure device makes the call nonsecure even if the caller's or recipient's phone is secure 1.

Authenticated (TLS signaling with integrity and authentication only)

Do

A call registers as secure only if every device in the call registers as secure; 1 nonsecure device makes the call nonsecure even if the caller's or recipient's phone is secure 1.

Verify

Suggested check: place a call between phones configured with the Authenticated profile. The shield icon on a phone means call signaling is encrypted with TLS while call media is unencrypted or only partially encrypted; some phone models show only the lock icon and never the shield 13.

Step 9 Configure SIP trunks

No, keep trunks non-secure

Do

A call registers as secure only if every device in the call registers as secure; 1 nonsecure device makes the call nonsecure even if the caller's or recipient's phone is secure 1.

Verify

Suggested check: leave existing SIP trunks in non-secure mode and route test calls across the trunks. The lock icon does not appear on calls traversing non-secure trunks 12.

Yes, configure encrypted TLS trunks

Do

For a CA-signed SIP TLS trunk, upload the CA root certificate as CallManager-trust and install the CA-signed CallManager certificate through OS Administration > Security > Certificate Management on both clusters 49. For a CUCM-to-CUBE TLS trunk, upload the CUBE certificate to Unified CM as CallManager-Trust 10. Cisco's CUCM-to-CUBE SIP TLS configuration note lists as a requirement that Unified CM be in mixed mode, with TCP 5061 open on transit firewalls and security and UCK9 licences on the CUBE 11.

Create a SIP trunk security profile with Device Security Mode set to Encrypted (TLS with AES128/SHA), which uses TLS as both incoming and outgoing transport type 50 56. The default incoming port for TLS in a SIP trunk security profile is 5061 51. The SIP trunk security profile's X.509 Subject Name field holds the peer certificate subject used to authenticate the device, accepting multiple names separated by space, comma, semicolon, or colon up to 4096 characters, and matches the peer cluster or CUBE certificate CN 10 58 59.

On the trunk, select the security profile, set the trunk destination port from 5060 to 5061, and check SRTP Allowed 10. Media encryption on a SIP trunk requires the SRTP Allowed check box on the trunk, and because SRTP keys travel in the SIP message body the signaling must be protected by TLS 54. Cisco recommends that a trunk with SRTP Allowed checked use an encrypted TLS profile so that keys and other security information are not exposed during call negotiation 55. Click Apply Config to reset the trunk 53.

Verify

A packet capture of a working SIP TLS trunk shows the TCP handshake, Client Hello, server and client certificate exchange, then encrypted Application Data carrying the SIP signaling 57. Verify that an end-to-end call over the trunk between encrypted phones shows the lock icon 1 12.

Rollback

On the trunk, change the destination port back to 5060, uncheck SRTP Allowed, re-select the non-secure SIP trunk security profile, and click Apply Config to reset the trunk 10 53.

Step 10 Maintain the CTL file during certificate regenerations

Do

On a mixed-mode cluster, run utils ctl update CTLFile on the publisher after regenerating CAPF, CallManager, or ITLRecovery and before restarting services 66:

  • After regenerating the CallManager certificate, run utils ctl update CTLFile before services are restarted 34.
  • After regenerating the CAPF certificate in mixed mode, the CTL file must be updated and the Cisco Certificate Authority Proxy Function, Cisco Trust Verification Service, and Cisco TFTP services restarted 33.
  • From 12.5, the ITLRecovery certificate is regenerated only on the publisher, and in a mixed-mode cluster the CTL file must be updated before services are restarted 35.

Verify

After certificate regeneration, reset encrypted and authenticated phones (via the Enterprise Parameters reset or bulk administration), and confirm registration in RTMT before regenerating the next certificate 36.

Step 11 Recover phone trust if certificates lose synchronization

Do

For endpoint trust recovery, utils itl reset localkey applies to non-secure clusters and utils ctl reset localkey applies to mixed-mode clusters 37. In a mixed-mode cluster, run utils ctl reset localkey on the publisher to regenerate the CTL file signed with the CallManager key (secondary SAST role) when the ITLRecovery certificate has changed and endpoints are locked out; once endpoints have that file, run utils ctl update CTLFile again to re-sign it with ITLRecovery 8 67.

In a non-secure cluster, run utils itl reset localkey to re-sign the ITL file with the CallManager key, confirm with show itl, reset phones from System > Enterprise Parameters, and restart the TFTP service 14.

Verify

Check the CTL file on recovering phones under Settings > Security Configuration > Trust List > CTL File and verify that the checksum matches the output of show ctl 23.

Step 12 Revert cluster to non-secure mode

Do

Before disabling mixed mode, re-apply non-secure profiles to phones and reset them 26. Reset any modified SIP trunks back to non-secure profiles 53. On the publisher, run utils ctl set-cluster non-secure-mode 19 61. After changing to non-secure mode, restart the TFTP and Cisco CallManager services on all nodes that run them and restart all IP phones to download the updated CTL file 22.

Verify

Verify that the Cluster Security Mode field in System > Enterprise Parameters or the processconfig SQL query no longer returns 1 44 63. After a change to non-secure mode, the CTL file still exists on servers and phones but contains no CCM+TFTP server certificates, and Cisco recommends deleting the CTL file from phones to avoid problems if certificates or cluster topology later change 20.

Rollback

Run utils ctl set-cluster mixed-mode on the publisher CLI to re-enter mixed mode 7 61.

Applicability

Applies to: Cisco Unified Communications Manager and Cisco Unified Communications Manager; Cisco Unified Border Element. Deployments: on-premises. Sources checked 2026-10-01. Tokenless CTL applies to Unified CM 10.0(1) and later 46. Returning to non-secure mode using utils ctl set-cluster non-secure-mode is documented for 10.x and later 19. CTL Provider discontinuation of USB tokens applies specifically to 14SU3 and later 48.

What remains uncertain

  • This is disputed: from Unified CM 12.0(1) the tokenless CTL file is signed by the ITLRecovery certificate and carries 2 SAST records (ITLRecovery and CallManager) 9, whereas other documentation describes the tokenless CTL file as signed by the publisher's CCM+TFTP certificate.
  • Whether current Unified CM releases enforce mixed mode when configuring TLS on SIP trunks without secure phones is not covered by the sources below.
  • Phone-model support for Authenticated mode shield icons versus lock icons is not covered by the sources below.

See also

Configures

  • Cisco unified cm — Security mode; CTL and ITL; phone and SIP trunk security profiles on Cisco Unified CM releases 14SU3 and 15

Referenced by

Sources

  1. 1
    A call registers as secure only if every device in the call registers as secure; one nonsecure device makes the call nonsecure even if the caller's or recipient's phone is secure.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security > interactions / call security status · Checked 2026-09-30
  2. 2
    The Cisco Certificate Authority Proxy Function service is activated on the publisher from Cisco Unified Serviceability > Tools > Service Activation; Online CA mode also needs the Cisco Certificate Enrollment Service.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > Activate or restart CAPF services · Checked 2026-09-30
  3. 3
    The per-phone Certificate Operation field offers Install/Upgrade to deploy an LSC, Delete to remove it, and Troubleshoot to diagnose certificate issues.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > CAPF settings on the phone · Checked 2026-09-30
  4. 4
    CAPF issues Locally Significant Certificates (LSCs) to supported Cisco IP phones, authenticates phones in mixed mode, upgrades existing LSCs and retrieves phone certificates for troubleshooting.
  5. 5
    CAPF runs in one of three modes: Cisco Authority Proxy Function (the default, where CAPF signs LSCs itself), Online CA (an external CA signs automatically) or Offline CA (CSRs are downloaded, signed externally and uploaded manually).
  6. 6
    LSC status can be checked on the Phone Configuration page, in CAPF reports, or from Find and List Phones.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > verify LSC / CAPF reports · Checked 2026-09-30
  7. 7
    The CLI command utils ctl set-cluster mixed-mode updates the CTL file and sets the cluster to mixed mode.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Mixed Mode > CLI commands table · Checked 2026-09-30
  8. 8
    utils ctl reset localkey, run on the publisher, regenerates the CTL file signed with the CallManager key (secondary SAST role) for use when the ITLRecovery certificate has changed and endpoints are locked out; once endpoints have that file, the CTL update command is run again to re-sign it with ITLRecovery.
    Command Line Interface Reference Guide for Cisco Unified Communications Solutions, Release 15 and SUs - Utils Commands · utils ctl reset localkey > Description and Usage Guidelines · Checked 2026-09-30
  9. 9
    From Unified CM 12.0(1) the tokenless CTL file is signed by the ITLRecovery certificate and carries two SAST records, ITLRecovery and CallManager.
    Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup · Cisco CTL Client Setup > SAST roles in tokenless CTL · Checked 2026-09-30
  10. 10
    For a CUCM-to-CUBE TLS trunk the CUBE certificate is uploaded to Unified CM as CallManager-Trust, the X.509 Subject Name matches the CUBE certificate CN, the trunk destination port changes from 5060 to 5061 and SRTP Allowed is checked.
    Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Steps 4, 9 and 10 · Checked 2026-09-30
  11. 11
    Cisco's CUCM-to-CUBE SIP TLS configuration note lists as a requirement that Unified CM be in mixed mode, with TCP 5061 open on transit firewalls and security and UCK9 licences on the CUBE.
    Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Prerequisites > Requirements · Checked 2026-09-30
  12. 12
    The lock icon on a phone means both call signaling (TLS) and call media (SRTP) are encrypted.
  13. 13
    The shield icon on a phone means call signaling is encrypted with TLS while call media is unencrypted or only partially encrypted; some phone models show only the lock icon and never the shield.
  14. 14
    When phones no longer trust the ITL signer, utils itl reset localkey re-signs the ITL file with the CallManager key; show itl confirms the reset, then phones are reset from System > Enterprise Parameters and the TFTP service is restarted.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Bulk reset of the ITL file · Checked 2026-09-30
  15. 15
    The ITL file is built automatically when the TFTP service is activated and is signed by the ITLRecovery certificate.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Initial Trust List / ITL file contents · Checked 2026-09-30
  16. 16
    The ITLRecovery key pair can be exported for disaster recovery with the CLI command file get tftp ITLRecovery.p12 to an SFTP server.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Back up ITLRecovery · Checked 2026-09-30
  17. 17
    ITLRecovery was chosen as the CTL signer because it does not change for secondary reasons such as a hostname change; before 12.0(1) regenerating the CallManager certificate could lock endpoints out.
    Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup · Cisco CTL Client Setup > tokenless CTL SAST roles · Checked 2026-09-30
  18. 18
    In mixed mode Unified CM uses TLS for signaling and SRTP for media.
  19. 19
    A tokenless mixed-mode cluster is returned to non-secure mode by running utils ctl set-cluster non-secure-mode on the publisher.
  20. 20
    After a change to non-secure mode the CTL file still exists on servers and phones but contains no CCM+TFTP server certificates, and Cisco recommends deleting the CTL file from phones to avoid problems if certificates or cluster topology later change.
    CUCM Cluster Changed from Mixed Mode to Non-Secure Mode Configuration Example · Background / CTL file after non-secure mode · Checked 2026-09-30
  21. 21
    Non-secure mode is the default security mode when Unified CM is first installed, and in it Unified CM provides no secure signaling or media services.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Non-Secure Mode (Default) · Checked 2026-09-30
  22. 22
    After changing to non-secure mode, the TFTP and Cisco CallManager services must be restarted on all nodes that run them and all IP phones restarted to download the updated CTL file.
    CUCM Cluster Changed from Mixed Mode to Non-Secure Mode Configuration Example · Configure > after the change · Checked 2026-09-30
  23. 23
    The CTL file on a phone can be checked under Settings > Security Configuration > Trust List > CTL File and its checksum compared with the output of show ctl.
  24. 24
    Before setting mixed mode the Certificate Authority Proxy Function (CAPF) service and the Certificate Trust List (CTL) Provider service must be enabled on the publisher.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Mixed Mode > prerequisites · Checked 2026-09-30
  25. 25
    Mixed mode requires Unified CM to be registered with Cisco Smart Software Manager or a Smart Software Manager satellite with export-controlled functionality enabled.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Mixed Mode > prerequisites · Checked 2026-09-30
  26. 26
    A phone security profile is applied in Device > Phone by selecting it in Device Security Profile, clicking Save and then Apply Config, and the phone must be reset for the change to take effect.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security > Apply Security Profile to Phone · Checked 2026-09-30
  27. 27
    The Authenticated device security mode provides integrity and authentication for the phone, using a TLS connection with NULL/SHA for signaling.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security Profile settings > Device Security Mode · Checked 2026-09-30
  28. 28
    The phone security profile's CAPF Authentication Mode options include By Null String, By Existing Certificate (Precedence to LSC) and By Existing Certificate (Precedence to MIC).
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security Profile settings > Authentication Mode · Checked 2026-09-30
  29. 29
    The Encrypted device security mode provides integrity, authentication and encryption for the phone.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security Profile settings > Device Security Mode · Checked 2026-09-30
  30. 30
    Phone security profiles are created in Unified CM Administration under System > Security > Phone Security Profile, using Add New or by copying an existing profile.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security > Set Up Phone Security Profile · Checked 2026-09-30
  31. 31
    Checking TFTP Encrypted Config in a phone security profile makes Unified CM encrypt the phone's downloads from the TFTP server.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security Profile settings > TFTP Encrypted Config · Checked 2026-09-30
  32. 32
    When a phone security profile's Device Security Mode is Authenticated or Encrypted, TLS is set as the transport automatically.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security Profile settings > Transport Type · Checked 2026-09-30
  33. 33
    After regenerating the CAPF certificate in mixed mode the CTL file must be updated and the Cisco Certificate Authority Proxy Function, Cisco Trust Verification Service and Cisco TFTP services restarted.
    Regenerate Certificates In Unified Communications Manager · CAPF certificate regeneration · Checked 2026-09-30
  34. 34
    In a mixed-mode cluster, after regenerating the CallManager certificate, utils ctl update CTLFile must be run before the services are restarted; a non-secure cluster skips the CTL update.
    Regenerate Certificates In Unified Communications Manager · CallManager certificate regeneration · Checked 2026-09-30
  35. 35
    From 12.5 the ITLRecovery certificate is regenerated only on the publisher, and in a mixed-mode cluster the CTL file must be updated before services are restarted.
    Regenerate Certificates In Unified Communications Manager · ITLRecovery certificate regeneration · Checked 2026-09-30
  36. 36
    After certificate regeneration, encrypted and authenticated phones must be reset (via the Enterprise Parameters reset or bulk administration), and registration should be confirmed in RTMT before regenerating the next certificate.
    Regenerate Certificates In Unified Communications Manager · CallManager certificate regeneration > phone reset · Checked 2026-09-30
  37. 37
    For endpoint trust recovery, utils itl reset localkey applies to non-secure clusters and utils ctl reset localkey applies to mixed-mode clusters.
    Regenerate Certificates In Unified Communications Manager · ITLRecovery certificate regeneration > recovery commands · Checked 2026-09-30
  38. 38
    After enabling mixed mode all IP phones must be restarted so they obtain the CTL file from the Unified CM TFTP service.
    Migrate CUCM Mixed Mode with Tokenless CTL · Configure > tokenless mixed mode steps · Checked 2026-09-30
  39. 39
    After running the mixed-mode CLI command, the TFTP and Cisco CallManager services must be restarted on all nodes in the cluster.
    Migrate CUCM Mixed Mode with Tokenless CTL · Configure > tokenless mixed mode steps · Checked 2026-09-30
  40. 40
    The enterprise parameter Prepare Cluster for Rollback to pre-8.0 makes the cluster publish ITL files with empty TVS and TFTP certificate sections so phones accept a new ITL, and it should be set back once the migration is complete.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Bulk certificate management and phone migration · Checked 2026-09-30
  41. 41
    Secure tones play only on phones configured as protected devices: three long beeps indicate a secure call and six short beeps a non-secure call.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Secure Tones and Icons · Secure Tones and Icons > Secure tones / protected devices · Checked 2026-09-30
  42. 42
    The CLI command show ctl displays the contents of the CTL file, including its checksum.
    Migrate CUCM Mixed Mode with Tokenless CTL · Verify · Checked 2026-09-30
  43. 43
    SIP OAuth mode is a separate Unified CM security mode, enabled with utils sipOAuth-mode enable on the publisher, that uses OAuth refresh tokens to authenticate Cisco Jabber and selected phone models.
  44. 44
    The CLI query run sql select paramname,paramvalue from processconfig where paramname='ClusterSecurityMode' returns 1 when the cluster is in mixed mode.
    Migrate CUCM Mixed Mode with Tokenless CTL · Verify · Checked 2026-09-30
  45. 45
    To move from a USB-token CTL to tokenless, endpoints must first download a token-generated CTL file uploaded on Unified CM 12.0(1) or later; only after that download can the cluster switch to tokenless with utils ctl update CTLFile.
    Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup · Cisco CTL Client Setup > note on tokenless CTL migration · Checked 2026-09-30
  46. 46
    Tokenless CTL, available from Unified CM 10.0(1), enables encryption of IP phone signaling and media without hardware USB eTokens.
    Migrate CUCM Mixed Mode with Tokenless CTL · Introduction · Checked 2026-09-30
  47. 47
    When mixed mode is set from the CLI, the CTL file is signed with the publisher's CCM+TFTP (server) certificate and contains no eToken certificates.disputed
    Migrate CUCM Mixed Mode with Tokenless CTL · Background Information / Configure section on tokenless CTL · Checked 2026-09-30
  48. 48
    As of Unified CM 14SU3 the Cisco CTL Provider service no longer supports CTL (USB) tokens, and tokenless is the default supported method.
    Regenerate Certificates In Unified Communications Manager · Background / note on CTL tokens · Checked 2026-09-30
  49. 49
    For a CA-signed SIP TLS trunk, the CA root certificate is uploaded as CallManager-trust and the CA-signed CallManager certificate is installed through OS Administration > Security > Certificate Management, on both clusters.
    Configure SIP TLS Trunk on the Communications Manager with a CA Signed Certificate · Configure > certificate upload steps · Checked 2026-09-30
  50. 50
    A SIP trunk security profile's Device Security Mode is Non Secure (TCP or UDP), Authenticated (TLS with NULL/SHA) or Encrypted (TLS with AES128/SHA).
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile settings > Device Security Mode · Checked 2026-09-30
  51. 51
    The default incoming port for TLS in a SIP trunk security profile is 5061.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile settings > Incoming Port · Checked 2026-09-30
  52. 52
    SIP trunk security is set in a SIP Trunk Security Profile under the System menu's security profile settings and applied to the trunk in the Device > Trunk SIP Trunk Configuration window.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · Trunk and Gateway SIP Security > Set Up SIP Trunk Security Profile · Checked 2026-09-30
  53. 53
    After a SIP trunk security profile is applied to a trunk, the trunk must be reset (Apply Config) for the change to take effect.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · Trunk and Gateway SIP Security > Apply SIP Trunk Security Profile · Checked 2026-09-30
  54. 54
    Media encryption on a SIP trunk requires the SRTP Allowed check box on the trunk, and because SRTP keys travel in the SIP message body the signaling must be protected by TLS.
    Configure SIP TLS Trunk on the Communications Manager with a CA Signed Certificate · Configure > SIP Trunk configuration · Checked 2026-09-30
  55. 55
    Cisco recommends that a trunk with SRTP Allowed checked use an encrypted TLS profile so that keys and other security information are not exposed during call negotiation.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · Trunk and Gateway SIP Security > SRTP Allowed note · Checked 2026-09-30
  56. 56
    Authenticated and Encrypted SIP trunk security profiles use TLS as both the incoming and outgoing transport type.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile settings > Incoming/Outgoing Transport Type · Checked 2026-09-30
  57. 57
    A packet capture of a working SIP TLS trunk shows the TCP handshake, Client Hello, server and client certificate exchange, then encrypted Application Data carrying the SIP signaling.
  58. 58
    In the intercluster SIP TLS example, each side's X.509 Subject Name is set to the Common Name of the peer cluster's certificate.
    Configure SIP TLS Trunk on the Communications Manager with a CA Signed Certificate · Configure > SIP Trunk Security Profile · Checked 2026-09-30
  59. 59
    The SIP trunk security profile's X.509 Subject Name field holds the peer certificate subject used to authenticate the device, and accepts multiple names separated by space, comma, semicolon or colon up to 4096 characters.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile settings > X.509 Subject Name · Checked 2026-09-30
  60. 60
    The utils ctl commands are not allowed while an upgrade is in progress.
  61. 61
    The utils ctl command must be run on the publisher; it is disabled on all other nodes.
  62. 62
    After any utils ctl CTL update, all Encrypted and Authenticated phones must be reset for the CTL file update to take effect.
  63. 63
    Mixed mode is confirmed when the Cluster Security Mode field in the Security Parameters pane of System > Enterprise Parameters shows the value 1.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Mixed Mode > verification · Checked 2026-09-30
  64. 64
    utils ctl commands (set-cluster mixed-mode, set-cluster non-secure-mode, update CTLFile) run only on the publisher, and encrypted and authenticated phones must be reset for CTL updates to take effect.
    Command Line Interface Reference Guide for Cisco Unified Communications Solutions, Release 15 and SUs - Utils Commands · utils ctl command entry (requirements and usage guidelines) · Checked 2026-10-01
  65. 65
    CAPF listens on TCP 3804 to issue Locally Significant Certificates to IP phones.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Cisco Unified Communications Manager TCP and UDP Port Usage · Table: Signaling, Media, and Other Communication Between Phones and Cisco Unified Communications Manager, row TCP 3804 · Checked 2026-10-01
  66. 66
    On a mixed-mode cluster, run utils ctl update CTLFile on the publisher after regenerating CAPF, CallManager or ITLRecovery and before restarting services.
    Regenerate Certificates In Unified Communications Manager · Mixed-mode requirement note · Checked 2026-10-01
  67. 67
    utils ctl reset localkey, run on the publisher, regenerates the CTL file signed with the CallManager key (secondary SAST) for when the ITLRecovery certificate has changed and endpoints are locked out. Run utils ctl update CTLFile again afterwards.

Documents

tier 2 current vendor documentation

Configure SIP TLS between CUCM-CUBE/CUBE-SBC

Cisco Systems · 2017-09-14 · accessed 2026-09-30

tier 2 current vendor documentation

Configure SIP TLS Trunk on the Communications Manager with a CA Signed Certificate

Cisco Systems · 2018-05-08 · accessed 2026-09-25

tier 2 current vendor documentation

CUCM Cluster Changed from Mixed Mode to Non-Secure Mode Configuration Example

Cisco Systems · 2015-04-10 · accessed 2026-09-30

tier 2 current vendor documentation

Migrate CUCM Mixed Mode with Tokenless CTL

Cisco Systems · 2024-09-11 · accessed 2026-09-30

tier 2 current vendor documentation

Regenerate Certificates In Unified Communications Manager

Cisco Systems · 2026-07-20 · accessed 2026-09-25

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup

Cisco Systems · 2024-03-22 · accessed 2026-09-30

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function

Cisco Systems · 2026-09-22 · accessed 2026-09-30

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security

Cisco Systems · 2026-09-22 · accessed 2026-09-24

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security

Cisco Systems · 2026-09-22 · accessed 2026-09-24

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Secure Tones and Icons

Cisco Systems · 2026-09-22 · accessed 2026-09-30

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes

Cisco Systems · 2026-09-22 · accessed 2026-09-24

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security

Cisco Systems · 2026-09-22 · accessed 2026-09-24

Cite this page

APA

WarmTransfer. (2026, October 1). Enabling mixed mode and encrypted calling in Unified CM. WarmTransfer. https://warmtransfer.net/guides/cucm-secure-calling-setup

BibTeX

@misc{warmtransfer-cucm-secure-calling-setup,
  title  = {Enabling mixed mode and encrypted calling in Unified CM},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cucm-secure-calling-setup},
  note   = {Verified 2026-10-01}
}