Source record · tier 2 current vendor documentation
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support
- Publisher
- Cisco
- URL
- https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html
- Published
- 2026-04-25
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco documentation; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- From Cisco IOS XE Cupertino 17.8.1a CUBE can verify a peer's certificate CN or SAN against configured permitted names with cn-san validate. in context
- The IOS XE 17.6+ CUBE guide configures SIP TLS with a PKI trustpoint, a voice class tls-profile referencing it, and a voice class tenant using session transport tcp tls. in context
- CUBE SIP TLS connections are inspected with show sip-ua connections tcp tls brief and show sip-ua connections tcp tls detail. in context
- CUBE supports TLS 1.3 from Cisco IOS XE 17.14.1a. in context
- On CUBE, SIP TLS uses a PKI trustpoint and a voice class tls-profile (trustpoint, optional cn-san-validate server). The profile is referenced from a voice class tenant that sets session transport tcp tls, with url sips for SIPS URLs. in context
- On CUBE, show sip-ua connections tcp tls detail shows each TLS connection's negotiated version and cipher, and show sip-ua connections tcp tls brief lists active connections and listen sockets. in context
- CUBE added TLS 1.3 and a TLS 1.2 minimum option in IOS XE 17.14.1a, configured with sip-ua transport tcp tls. From IOS XE 26.1.1, TLS 1.0 and 1.1 are not allowed in the default configuration. in context
- For cn-san-validate server to accept Genesys, CUBE must trust the CA that signs the Genesys certificates (Amazon Trust Services on Dynamic Cloud Voice), usually via a trustpoint authenticated with that root. inferred in context
- When CUBE establishes an inbound TLS session with CN-SAN verification, it skips the trusted IP address check. in context
- CUBE's cn-san-validate option takes server (validate the identity of the outbound peer), client (validate the identity of the inbound peer) or bidirectional (both), and CN/SAN validation is not on by default. in context
- From Cisco IOS XE 26.1.1, CUBE's default configuration no longer supports TLS 1.0 and 1.1 or their associated ciphers; using them requires 'system mode insecure'. in context
- On CUBE, 'show sip-ua connections tcp tls detail' shows each SIP TLS connection's negotiated TLS version, cipher, key type and curve, and 'clear sip-ua tcp tls connection' takes an id or target to tear one down. in context
- CUBE's sip-ua transport command accepts 'transport tcp tls' followed by v1.0, v1.1, v1.2 (optionally with 'minimum') or v1.3 to pin or set a floor for the TLS version. in context
Cite this source record
APA
WarmTransfer. (2026, April 25). Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cube-xe-sip-tls-support
BibTeX
@misc{warmtransfer-cisco-cube-xe-sip-tls-support,
title = {Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-cube-xe-sip-tls-support},
note = {Cisco, accessed 2026-09-24}
}