Source record · tier 2 current vendor documentation
Regenerate Certificates In Unified Communications Manager
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/214231-certificate-regeneration-process-for-cis.html
- Published
- 2026-07-20
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Cisco website terms of use; copyrighted; no-redistribution; short excerpts and locators only
Source notes citing this source
- Devices that already had a bad ITL before regeneration do not register back to the cluster until their ITL is removed. in context
- When Unified CM integrates with Unified CCX, the regenerated Unified CM Tomcat certificates must be uploaded to the CCX tomcat-trust store. in context
- Whether the cluster is mixed mode is read from the Cluster Security Mode enterprise parameter under Security Parameters, where 1 means mixed mode and 0 means non-secure. in context
- The TAC technote warns against regenerating the CallManager and TVS certificates at the same time in versions 8.x through 11.5. in context
- The CTL file has entries for the CallManager, TFTP, CAPF, ITLRecovery and SAST roles but not for TVS. in context
- When cleaning up expired certificates, only expired trust certificates are deleted, one node at a time. The base identity certificates (CallManager, Tomcat, IPsec, CAPF, TVS) are never deleted. in context
- Cisco's certificate regeneration technote says all endpoints should be powered on and registered before certificates are regenerated. in context
- DRS uses the IPsec certificate for its public and private key encryption, so after regenerating IPsec the technote restarts Cisco DRF Master on the publisher and then Cisco DRF Local on every node. in context
- From Release 12.0 onward, the ITL file is signed by the ITLRecovery certificate. in context
- In a mixed-mode cluster, after the CAPF, CallManager or ITLRecovery certificate is regenerated the CTL file must be updated with utils ctl update CTLFile on the publisher. in context
- The technote says to reboot the phones after each phone-trust certificate is regenerated and to wait until RTMT shows registration is complete before regenerating the next certificate. in context
- The TAC technote (rev 7.0, scoped to 15.0 and later) tells administrators to restart Cisco CallManager, CTIManager, Trust Verification Service and TFTP, publisher first, after regenerating the CallManager certificate, and then to reboot the phones. disputed in context
- The TAC technote tells administrators to restart Tomcat on every node with utils service restart Cisco Tomcat after regenerating the Tomcat certificate, publisher first and then subscribers. in context
- When SSO or OAuth is configured, the technote also requires restarting Cisco SSOSP Tomcat after the Tomcat certificate is regenerated. in context
- In its sequence of phone-trust certificates (CAPF, CallManager, TVS), the TAC technote tells administrators to regenerate the TVS certificate last, and it documents ITLRecovery separately as a publisher-only certificate. in context
Cite this source record
APA
WarmTransfer. (2026, July 20). Regenerate Certificates In Unified Communications Manager. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-technote-214231-regenerate-cucm-certs
BibTeX
@misc{warmtransfer-cisco-technote-214231-regenerate-cucm-certs,
title = {Regenerate Certificates In Unified Communications Manager},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-technote-214231-regenerate-cucm-certs},
note = {Cisco Systems, accessed 2026-09-25}
}