Source record · tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - FIPS Mode Setup
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_fips-mode-setup_su2_reorg.html
- Published
- 2026-09-22
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Common Criteria mode (utils fips_common_criteria enable) needs FIPS mode enabled first and does not work with TLS 1.3. in context
- Under Enhanced Security Mode, contact search authentication is enabled by default, and the default remote audit logging transport changes to TCP unless TLS is already configured. in context
- Enhanced Security Mode (utils EnhancedSecurityMode enable) runs on FIPS-enabled systems. It requires passwords of 14 to 127 characters with lowercase, uppercase, digit and special characters, blocks reuse of the last 24 passwords, and sets a 60-day maximum age. in context
- Enabling FIPS mode regenerates certificates and the SSH key automatically, so third-party CA-signed certificates must be uploaded again afterwards. in context
- The Security Guide advises disabling FIPS mode before upgrading to a version that is not FIPS-compliant. in context
- utils fips enable reboots the node, runs certification self-tests at startup, checks cryptographic module integrity and regenerates keying material. in context
- The Release 15 Security Guide describes Unified CM FIPS mode as FIPS 140-2 mode, and its New and Changed Information page does not mention FIPS 140-3. in context
- FIPS mode requires a security password of at least 14 characters, and every node in the cluster must be in the same mode, all FIPS or all non-FIPS. in context
- Because the Release 15 guide labels Unified CM FIPS mode as FIPS 140-2 and NIST moved all 140-2 certificates to the Historical List on 22 September 2026, an organisation with a FIPS 140-3 procurement requirement cannot assume Unified CM FIPS mode meets it without checking Cisco's current CMVP certificate status. inferred in context
- In FIPS mode, MD5 and DES do not work. SNMPv3 must use SHA authentication with AES128 privacy, and Certificate Remote Enrolment is not supported. in context
- If any FIPS self-test fails, the Unified CM server halts. in context
- In a cluster, enable FIPS on the publisher first and wait for phones to re-register before enabling it on other nodes. Do not run security mode commands on all nodes at once. in context
Cite this source record
APA
WarmTransfer. (2026, September 22). Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - FIPS Mode Setup. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-sec15-fips-mode
BibTeX
@misc{warmtransfer-cisco-cucm-sec15-fips-mode,
title = {Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - FIPS Mode Setup},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-sec15-fips-mode},
note = {Cisco Systems, accessed 2026-09-25}
}