Source record · tier 2 current vendor documentation
Understand CUCM Security By Default and ITL Operation and Troubleshooting
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html
- Published
- 2023-07-14
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Centralized TFTP only works in an ITL-homogeneous environment: all servers on Unified CM 8.x or later, or all on releases before 8.x. in context
- The SBD technote gives the phone menu path Settings > Security Configuration > Trust List for manually deleting the ITL, noting that the path varies by phone model. in context
- Cisco warns never to regenerate the CallManager.pem and TVS.pem certificates at the same time; after changing either, TFTP and TVS services are restarted and phones reset to pick up the new ITL. in context
- Cisco's SBD technote states there is no Cisco-provided method to delete the ITL from all phones remotely; deletion is manual per phone, or a factory reset where the phone's settings access is restricted. in context
- With SBD, phones request a signed configuration file named SEP<MAC>.cnf.xml.sgn, or SEP<MAC>.cnf.xml.enc.sgn when configuration encryption is in use. in context
- When the CallManager certificate is regenerated, phones cannot verify the newly signed files directly and contact TVS to authenticate the new certificate before accepting the updated ITL. in context
- Phone console logs show successful trust-file validation with strings such as 'File sign verify SUCCESS' for the ITL and 'SECD: verifyFile: verify SUCCESS' for configuration files checked against the ITL. in context
- Cisco TAC states the ITL file needs deleting from a phone only when all of these hold: the phone's ITL signature does not match the TFTP server's ITL, the TVS signature in the ITL does not match the certificate presented, the phone shows verification failures, and no backup of the old TFTP private key exists. in context
- Where the ITL must be removed from a phone that no longer trusts the cluster, the phone's buttons must be pressed manually on the phone to delete it. in context
- The Trust Verification Service (TVS) runs on Unified CM on TCP port 2445 and authenticates certificates the phone does not already trust, so the phone need not hold a full trust store. in context
Cite this source record
APA
WarmTransfer. (2023, July 14). Understand CUCM Security By Default and ITL Operation and Troubleshooting. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-technote-116232-sbd-itl
BibTeX
@misc{warmtransfer-cisco-technote-116232-sbd-itl,
title = {Understand CUCM Security By Default and ITL Operation and Troubleshooting},
author = {{WarmTransfer}},
year = {2023},
url = {https://warmtransfer.net/knowledge/sources/cisco-technote-116232-sbd-itl},
note = {Cisco Systems, accessed 2026-09-24}
}