<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is regeneration of CAPF after mixed mode needed? in IP Telephony and Phones</title>
    <link>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3932235#M382760</link>
    <description>&lt;P&gt;Is regeneration of CAPF and re-sign by CA needed after changing CUCM to mixed mode, if previously LSC is installed during non-secure mode?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Phones were previously signed with CA signed LSC and had 802.1x enabled for NAC. CUCM v12.5 was in non secured mode.&lt;/P&gt;&lt;P&gt;2. Customer requires encryption on the phones thus we have converted the CUCM v12.5 to mixed mode&lt;/P&gt;&lt;P&gt;3. Phones are not able to register after we applied the secure sip profile. NAC is working as phone is still getting IP but just cannot register to CUCM.&amp;nbsp; If we delete the LSC from the phone, the phone can register using secure profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phone (with LSC) getting the below error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7851 ERR Sep 23 15:01:20.320158 (348:2292) SECUREAPP-Secure Connection Handshake failed.&lt;BR /&gt;7852 NOT Sep 23 15:01:20.322478 (348:2292) SECUREAPP-Close and free connection handler at 0x2a1c63b0&lt;BR /&gt;7853 NOT Sep 23 15:01:20.323210 (348:2292) SECUREAPP-Sec SSL Close Connection successful.&lt;BR /&gt;7854 ERR Sep 23 15:01:20.323699 (348:2292) SECUREAPP-PXY_SSL_CLNT: SSL CLNT ERR, srvr[10.178.23.16]&lt;BR /&gt;7855 ERR Sep 23 15:01:20.324523 (348:2292) SECUREAPP-SECERR_DETAIL: ** SEC-ERR: code:[11]([UNKNOWN_ERR]) subcode:[0]([N/A])&lt;BR /&gt;7856 ERR Sep 23 15:01:20.325041 (348:2292) SECUREAPP-SECERR_DESC: ** SEC-ERR: desc [ssl setup failed]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CUCM, we are getting this:&lt;/P&gt;&lt;P&gt;07275357.000 |14:58:46.457 |AppInfo&amp;nbsp; |[3, 100, 247, 138]: HandleSSLError - Certificate verification failed:(Verification error:2)- unable to get issuer certificate for 10.178.99.71:51537&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ITL and CTL checksum on the phone are the same as the publisher, so no error on that.&amp;nbsp; This is confirmed by the below phone logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UREAPP-validateSignedCTL: new TL matches old, not updating&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2019 03:01:04 GMT</pubDate>
    <dc:creator>esther.tan</dc:creator>
    <dc:date>2019-10-02T03:01:04Z</dc:date>
    <item>
      <title>Is regeneration of CAPF after mixed mode needed?</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3932235#M382760</link>
      <description>&lt;P&gt;Is regeneration of CAPF and re-sign by CA needed after changing CUCM to mixed mode, if previously LSC is installed during non-secure mode?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Phones were previously signed with CA signed LSC and had 802.1x enabled for NAC. CUCM v12.5 was in non secured mode.&lt;/P&gt;&lt;P&gt;2. Customer requires encryption on the phones thus we have converted the CUCM v12.5 to mixed mode&lt;/P&gt;&lt;P&gt;3. Phones are not able to register after we applied the secure sip profile. NAC is working as phone is still getting IP but just cannot register to CUCM.&amp;nbsp; If we delete the LSC from the phone, the phone can register using secure profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phone (with LSC) getting the below error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7851 ERR Sep 23 15:01:20.320158 (348:2292) SECUREAPP-Secure Connection Handshake failed.&lt;BR /&gt;7852 NOT Sep 23 15:01:20.322478 (348:2292) SECUREAPP-Close and free connection handler at 0x2a1c63b0&lt;BR /&gt;7853 NOT Sep 23 15:01:20.323210 (348:2292) SECUREAPP-Sec SSL Close Connection successful.&lt;BR /&gt;7854 ERR Sep 23 15:01:20.323699 (348:2292) SECUREAPP-PXY_SSL_CLNT: SSL CLNT ERR, srvr[10.178.23.16]&lt;BR /&gt;7855 ERR Sep 23 15:01:20.324523 (348:2292) SECUREAPP-SECERR_DETAIL: ** SEC-ERR: code:[11]([UNKNOWN_ERR]) subcode:[0]([N/A])&lt;BR /&gt;7856 ERR Sep 23 15:01:20.325041 (348:2292) SECUREAPP-SECERR_DESC: ** SEC-ERR: desc [ssl setup failed]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CUCM, we are getting this:&lt;/P&gt;&lt;P&gt;07275357.000 |14:58:46.457 |AppInfo&amp;nbsp; |[3, 100, 247, 138]: HandleSSLError - Certificate verification failed:(Verification error:2)- unable to get issuer certificate for 10.178.99.71:51537&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ITL and CTL checksum on the phone are the same as the publisher, so no error on that.&amp;nbsp; This is confirmed by the below phone logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UREAPP-validateSignedCTL: new TL matches old, not updating&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 03:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3932235#M382760</guid>
      <dc:creator>esther.tan</dc:creator>
      <dc:date>2019-10-02T03:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is regeneration of CAPF after mixed mode needed?</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3932323#M382763</link>
      <description>Hi Esther,&lt;BR /&gt;&lt;BR /&gt;Was this cluster in mixed mode ever before and had CTL file ? If so, then you need to delete the CTL file before moving to mixed mode again. Please refer the below link for more detailed procedure:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/118893-technote-cucm-00.html#anc5" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/118893-technote-cucm-00.html#anc5&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Rajan&lt;BR /&gt;Please rate all useful posts by clicking the star below and mark solutions as accepted wherever applicable&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Sep 2019 08:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3932323#M382763</guid>
      <dc:creator>Rajan</dc:creator>
      <dc:date>2019-09-30T08:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is regeneration of CAPF after mixed mode needed?</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3933459#M382829</link>
      <description>&lt;P&gt;Hi Rajan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No. There was no CTL file before we switched to mixed mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Esther&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 03:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/is-regeneration-of-capf-after-mixed-mode-needed/m-p/3933459#M382829</guid>
      <dc:creator>esther.tan</dc:creator>
      <dc:date>2019-10-02T03:01:51Z</dc:date>
    </item>
  </channel>
</rss>

