Source record · tier 2 current vendor documentation
Unified Communications Manager ITL Enhancements in Version 10.0(1)
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html
- Published
- 2014-04-08
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- utils itl reset localkey uses the ITLRecovery private key from the ITLRecovery.p12 file stored on the publisher. in context
- utils itl reset takes the current ITL from the publisher, strips its signature, re-signs the contents with the ITLRecovery private key and copies the new ITL to the TFTP directories on all active TFTP nodes. in context
- utils itl reset remotekey retrieves an ITLRecovery.p12 file from an external SFTP server and uses it in place of the local copy. in context
- As documented for 10.0(1), the ITLRecovery certificate had a five-year validity. in context
- The ITLRecovery key was introduced in Unified CM 10.0(1), is created during install or upgrade, and does not change when the hostname or DNS changes. in context
- The ITL Recovery key was introduced in Unified CM 10.0(1). It is designed not to change when hostname, DNS or similar changes occur. in context
- utils itl reset localkey uses the ITLRecovery.p12 file stored on the publisher. utils itl reset remotekey retrieves the key from an external SFTP server. in context
- In 10.0(1), Unified CM added a hold timer that prevents regenerating another certificate on the same node within five minutes of the previous regeneration. in context
- The 10.0(1) technote says phones have TVS as a secondary way to authenticate files, whichever certificate is regenerated first. This is why changing one ITL-relevant certificate at a time is recoverable. in context
- The rule against changing CallManager and TVS together follows from the ITL trust model. A phone that sees an unfamiliar ITL signer falls back to TVS, so if the TVS certificate changes in the same window the phone has no trusted path left. inferred in context
- Recovering phones from an untrusted state requires the ITL Recovery key. Cisco's tech note says to keep a copy (file get tftp ITLRecovery.p12) in addition to DRS backups. in context
Cite this source record
APA
WarmTransfer. (2014, April 8). Unified Communications Manager ITL Enhancements in Version 10.0(1). WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-technote-117598-itl-enhancements-10
BibTeX
@misc{warmtransfer-cisco-technote-117598-itl-enhancements-10,
title = {Unified Communications Manager ITL Enhancements in Version 10.0(1)},
author = {{WarmTransfer}},
year = {2014},
url = {https://warmtransfer.net/knowledge/sources/cisco-technote-117598-itl-enhancements-10},
note = {Cisco Systems, accessed 2026-09-24}
}