09-30-2014 01:35 PM - edited 03-17-2019 12:21 AM
Hello,
currently we are running CUCM 9.1.2 Unrestricted, it does not support SRTP, secure signalling etc. I would like to use LSCs issued by my own CA to authenticate our phones against RADIUS with EAP-TLS. As far as I understand how CAPF works, I need to enable mixed security mode in my cluster and create CTL (or I only need to choose "Update CTL file" option in Cisco CTL Client to create new CTL and upload it to CUCM?). Is it possible to do that if my cluster is unrestricted? Do I still need to buy bunch of USB Tokens to sign the CTL?
Thank you.
09-30-2014 03:48 PM
My understanding is that you need restricted version for all security features as the unrestricted does not include any crypto.
Chris
09-30-2014 08:37 PM
Thank you for the answer, in my case I only need to distribute LSCs to the phones for 802.1x authentication. As far as I understand, it is possible to just update the CTL file with Cisco CTL Client utility.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide