Source record · tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_default-security-setup_su2_reorg.html
- Published
- 2026-09-22
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- The Release 15 Security Guide states that autoregistration is supported in both mixed mode and nonsecure mode and that the default configuration file is signed. disputed in context
- The ITL file is created automatically when the TFTP service is activated at cluster install, and is rebuilt automatically when its content changes; no security feature has to be enabled for it. in context
- The CallManager certificate carried in the ITL lets the phone authenticate the ITL file signature and the phone configuration file signature. in context
- Cisco IP phones download the ITL file during a reset, a restart, or after downloading the CTL file. in context
- A phone with no CTL file trusts the first ITL file it receives automatically; a phone that has a CTL file uses the CTL to authenticate the ITL signature. in context
- A bulk ITL reset with the CLI command utils itl reset is used when phones no longer trust the ITL file signer, to re-establish trust between phones and the Unified CM TFTP service. in context
- After running the ITL reset command, the administrator resets devices from System > Enterprise Parameters > Reset so phones download the newly signed ITL file. in context
- In Release 15 the ITL file is signed by the ITLRecovery certificate. in context
- Unified CM Administration can filter phones by ITL File Status under Device > Phone, with values Match, MisMatch, Not Installed and Unknown. in context
- The ITL carries TVS certificates so the phone can reach TVS securely; the CAPF certificate supports configuration file encryption but is not required in the ITL because TVS can authenticate it. in context
- In Release 15 the ITLRecovery certificate validity is 20 years by default, configurable to 5, 10, 15 or 20 years, and the certificate is carried forward on upgrade. in context
- Setting the enterprise parameter Prepare Cluster for Rollback to pre-8.0 to True makes phones download a special ITL with empty TVS and TFTP certificate sections, after which they accept unsigned configuration files and any new ITL. in context
- For moving phones between clusters, the Release 15 Security Guide calls the Prepare Cluster for Rollback to pre-8.0 parameter the most preferred option. in context
- Security By Default gives supported Cisco IP phones a basic level of security with no extra configuration, including default TFTP file authentication, optional configuration file encryption and certificate verification. in context
- A bulk ITL reset is run with utils itl reset localkey or utils itl reset remotekey, checked with show itl, followed by Reset on the Enterprise Parameters page so devices restart and download the new ITL, and a restart of the TFTP service and devices. in context
- The ITL file is used for initial trust between endpoints and Unified CM and contains the TFTP, TVS and CAPF certificates plus the ITLRecovery certificate used to sign it. in context
- Deleting trust files from phones is a last resort: the bulk ITL reset from Unified CM should be tried before touching phones individually, because a manual deletion must be done at each phone. inferred in context
- Some phones do not pick up the latest ITL file and keep the old one when ITL files are updated, for example on renewal of the CallManager certificate. in context
- A phone moved from one Unified CM cluster to another can fail because the new cluster's ITL file is not signed by the signer in the ITL the phone already holds. in context
- Setting the enterprise parameter Prepare Cluster for Rollback to pre-8.0 to True makes the cluster publish an ITL with blank entries, and phone services that use HTTPS do not work while it is enabled. in context
- When a phone cannot verify a signature or certificate from its CTL or ITL, it contacts a TVS server to verify it. in context
- The Trust Verification Service runs on Unified CM nodes and authenticates certificates on behalf of the phone, so the phone only needs to trust TVS instead of holding every trusted certificate. in context
- Phones that do not support Security By Default are served a nonsigned default configuration file under autoregistration. in context
- The ITL file contains the ITLRecovery certificate, the CallManager certificate of the TFTP server, every TVS certificate in the cluster and the CAPF certificate. It does not list Tomcat. in context
- When phones no longer trust the ITL signer, utils itl reset localkey re-signs the ITL with the ITLRecovery key. After a TFTP restart and a device reset, phones download that ITL and register correctly. in context
- The ITLRecovery certificate validity was extended from 5 years to 20 years so that it stays the same for longer. Selectable values are 5, 10, 15 or 20 years. in context
- The Trust Verification Service runs on Unified CM and authenticates certificates on behalf of the IP phone, so phone resources do not limit how many certificates can be trusted. in context
- When phones lose trust in the cluster, utils itl reset localkey or utils itl reset remotekey generates a new ITL recovery file and re-establishes trust between phones and TFTP. in context
- The ITL file holds the ITLRecovery certificate, the TFTP server's CallManager certificate, all TVS certificates and the CAPF certificate. Phones use it to authenticate configuration-file signatures and, through TVS, application servers. in context
- The enterprise parameter Prepare Cluster for Rollback to pre-8.0 gives phones an ITL with empty TVS and TFTP sections, so they accept unsigned configuration files and any new ITL. Cisco recommends it before moving phones between clusters. in context
Cite this source record
APA
WarmTransfer. (2026, September 22). Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-default-security
BibTeX
@misc{warmtransfer-cisco-cucm-secguide-15-default-security,
title = {Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-default-security},
note = {Cisco Systems, accessed 2026-09-24}
}