cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
271
Views
0
Helpful
1
Replies

Are CTL / ITL certificates used by AnyConnect? Why are there two hashes in phone config?

esa_fresa
Level 1
Level 1

Are the CTL / ITL certificates in CUCM the same certificates that are put into the phone configuration to be used by AnyConnect for IP Phone vpn?

 

And a follow up question. Why does my phone config have two certificate hashes?

<credentials>

<hashAlg>0</hashAlg>

<certHash1>Hy2hWyNUwlvxxx...=</certHash1>

<certHash2>SznAL6KKbv9kexxx...=</certHash2>

</credentials>

1 Accepted Solution

Accepted Solutions

Manish Gogna
Cisco Employee
Cisco Employee

Hi,

Specific certificate requirements for CUCM and ASA when using ANyconnect are detailed here

http://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/115785-anyconnect-vpn-00.html#anc5

These are different from the ITL/CTL certs which are used by all IP phones on cucm cluster.

 

HTH

Manish

 

View solution in original post

1 Reply 1

Manish Gogna
Cisco Employee
Cisco Employee

Hi,

Specific certificate requirements for CUCM and ASA when using ANyconnect are detailed here

http://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/115785-anyconnect-vpn-00.html#anc5

These are different from the ITL/CTL certs which are used by all IP phones on cucm cluster.

 

HTH

Manish