Source record · tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/12_5_1SU2/cucm_b_security-guide-1251SU2/cucm_b_security-guide-1251SU2_chapter_0100.html
- Published
- 2024-03-22
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- Cisco documentation; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- From Unified CM 12.0(1) the tokenless CTL file is signed by the ITLRecovery certificate and carries two SAST records, ITLRecovery and CallManager. in context
- ITLRecovery was chosen as the CTL signer because it does not change for secondary reasons such as a hostname change; before 12.0(1) regenerating the CallManager certificate could lock endpoints out. in context
- To move from a USB-token CTL to tokenless, endpoints must first download a token-generated CTL file uploaded on Unified CM 12.0(1) or later; only after that download can the cluster switch to tokenless with utils ctl update CTLFile. in context
Cite this source record
APA
WarmTransfer. (2024, March 22). Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-sec1251su2-ctl-client
BibTeX
@misc{warmtransfer-cisco-cucm-sec1251su2-ctl-client,
title = {Security Guide for Cisco Unified Communications Manager, Release 12.5(1)SU2 - Cisco CTL Client Setup},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-sec1251su2-ctl-client},
note = {Cisco Systems, accessed 2026-09-30}
}