12-12-2023 04:15 AM
Hi,
I want to enable support for TLS 1.2 and/or 1.3 and disable support for TLS 1.1. If not possible, at least disable TLS 1.0. The CUCM version is 11.5. Phone models include 7906, 7911, and 6901. All security profiles are set to non-secure
Thanks
12-12-2023 04:52 AM - edited 12-12-2023 05:00 AM
But you should first check, if your phones support TLS 1.2 or higher. If not, you cannot disable it on CUCM just like that. And since your phones are EoL anyways, you should start by replacing them with 78xx or 88xx phones.
12-12-2023 08:27 AM
Hi
"But you should first check, if your phones support TLS 1.2 or higher"
Since all phone security profile and trunk security profile are set to non-secure , does it matter ?
Thanks
12-12-2023 09:55 AM - edited 12-12-2023 11:46 PM
Yes it matters. Otherwise @b.winter would not have mentioned it. For example the phones uses it to get the configuration from the CM, but also for other things.
12-12-2023 11:21 PM - edited 12-12-2023 11:22 PM
As @Roger Kallberg said, it does matter. There is more communication, than secure SIP / SCCP and sRTP. Just think about the directory services (personal, directory phone book, ...).
If you are sure, that the phones communicate completely unsecure, you can disable TLS 1.1 or lower. But nobody can give you a general yes or no, because this always depends on the individual environment and the configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide