11-17-2015 03:46 AM - edited 03-17-2019 04:55 AM
Hi
I have a customer that have two CUCM clusters, both running 9.1.1 (long story why it ended up so).
One cluster have not enabled "Cisco CTL Provider" or "Cisco Certificate Authority Proxy Function" and the other have not. Why its like this i don't know.
The one cluster where both of these services are enable we have started to get warnings about "capf certificate is about to expire".
Both clusters are working fine.
We don't use Sip Secure and most (almost every) device uses SCCP.
What would happen if disable "Cisco CTL Provider" and "Cisco Certificate Authority Proxy Function"?
Solved! Go to Solution.
11-17-2015 04:57 AM
Hi Tony,
Please chck under System > Clusterwide parameters on cucm admin page
If the value is 0, then it should be okay as per what you see on the IP phones.
Manish
11-17-2015 04:09 AM
Hi Tony,
CAPF works in tandem with CTL as explained in detail here
http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/10_0_1/secugd/CUCM_BK_C68276B4_00_cucm-security-guide-100/CUCM_BK_C68276B4_00_cucm-security-guide-100_chapter_01010.html#CUCM_TP_CBFA1090_00
You don't need these services if the server is not running in secure or mixed-mode.
Manish
- Do rate helpful posts -
11-17-2015 04:48 AM
Hi Manish
Just to be sure:
I have located all the phones and every device has LSC status "none" or nothing in the "CAPF Auth String" colom.
Does that mean i don't have a single device depending on CTL or CAPF?
/Tony
11-17-2015 04:57 AM
Hi Tony,
Please chck under System > Clusterwide parameters on cucm admin page
If the value is 0, then it should be okay as per what you see on the IP phones.
Manish
11-17-2015 05:12 AM
11-17-2015 05:32 AM
Hi Tony,
Yes. As Manish mentioned, if your Cluster Security Mode is 0, then you can safely stop the CAPF service because your cluster is non-secure and does not need this service to be active.
HTH
Rajan
12-01-2015 04:15 AM
Hi Rajan
I have stopped the services and nothing happend. Thats good news.
The alarm about an expiering certificat still pops up in prime though.
/Tony
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide