Source record · tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_ucm-security-modes_reorg.html
- Published
- 2026-09-22
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Mixed mode is confirmed under System > Enterprise Parameters, where the Cluster Security Mode value is 1. in context
- In mixed mode the CTL file must be updated whenever a new certificate is uploaded, using utils ctl update CTLFile, which distributes the updated CTL to all cluster nodes. in context
- A fresh Unified CM installation runs in non-secure mode by default. in context
- Mixed mode is enabled from the publisher CLI with utils ctl set-cluster mixed-mode, which updates the CTL file, and reverted with utils ctl set-cluster non-secure-mode. in context
- Mixed mode, also called secure mode, supports both secure and non-secure endpoints in the same cluster. in context
- Before converting to mixed mode, Unified CM must be registered to Cisco Smart Software Manager or a satellite with a registration token that has Allow Export-Controlled functionality enabled. in context
- Converting to mixed mode requires the Cisco CAPF service and the Cisco CTL service to be activated on the publisher. in context
- The cluster security mode is shown under System > Enterprise Parameters as Cluster Security Mode, 1 for mixed mode and 0 for non-secure, and cannot be set on that page. in context
- The CLI command utils ctl update CTLFile updates the CTL file on each node in the cluster. in context
- The CLI command utils ctl set-cluster mixed-mode updates the CTL file and sets the cluster to mixed mode, and utils ctl set-cluster non-secure-mode updates the CTL file and returns it to non-secure mode. in context
- In mixed mode phones download the CTL file from TFTP, and if the CTL contains a TFTP server entry with a self-signed certificate the phone requests a signed configuration file. in context
- Non-secure mode is the default Unified CM cluster security mode after installation and provides no secure signalling or media; mixed mode supports both secure and non-secure endpoints. in context
Cite this source record
APA
WarmTransfer. (2026, September 22). Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-security-modes
BibTeX
@misc{warmtransfer-cisco-cucm-secguide-15-security-modes,
title = {Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-security-modes},
note = {Cisco Systems, accessed 2026-09-24}
}