cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
613
Views
2
Helpful
9
Replies

CUCM IPSEC Certificate

extremum
Level 1
Level 1

Hello ,

Our version is cucm 14 su4 we do not use IPSEC feature , in previos version IPSEC cert. was using for DRF but now DRF is managing by Tomcat so can we delete IPSEC cert. from entire cluster ?

 

Best Regards ,

 

9 Replies 9

Where have you seen that DRF don’t use the IPSEC certificate? From what I know it still uses this certificate.



Response Signature


Roger maybe I am wrong , but can you explain IPSEC regarding below chart ;

 

extremum_0-1736366812433.png

 

What is the number of the breakout season from Live? I rather look at it first hand before I comment.



Response Signature


As far as I know, from 14 FCS and above, if IPsec is not used, it can be removed. However, I have never deleted them for the customers, and I'm not sure how this can be done. I leave them untouched

NithinEluvathingal_0-1736403202367.png

 

NithinEluvathingal_1-1736403259737.png

 

https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/14SU2/cucm_b_security-guide-14su2/cucm_m_certificates.html



Response Signature


How would one actually remove the IPsec certificate? From what I can see on our system, that runs 15SU3 there is no delete option.

image.png

@Nithin Eluvathingal based on the document you shared it looks like DRF (DRS) from version 14SU2 uses the Tomcat-ECDSA certificate.

image.pngSnag_2772b1.png



Response Signature


Maybe from CLI ? 

set cert delete does not work ?

From what I know that is only possible for certificates that are in a trust store named with <something>-trust, for example CallManager-trust or tomcat-trust.

If I run the command from CLI that should from what I understand remove the IPsec cert I get this.

image.png

If I list the certificates that the system uses I think that the unit and file names are correctly entered.

image.png



Response Signature


@Roger Kallberg   I'm unsure how it can be deleted even i haven't seen an option to delete it from the GUI, . My understanding, like the OP, is that it can be deleted based on the slides I have seen.

Like the response of a Cisco employee on the community, it could be doable from the CLI. I cannot test this, but if you have the option, please try it and let us know.

NithinEluvathingal_0-1736413869112.png

https://community.cisco.com/t5/ip-telephony-and-phones/removing-certificates-from-cucm/td-p/2934514

For details on how to delete it and what exactly Cisco meant by this, I guess Cisco TAC could provide an answer.

@extremum ,Keep it untouched  or raise a question with TAC if you really want to remove it.



Response Signature


extremum
Level 1
Level 1

I will keep it for now , if someone deleted and experienced please update then I can remove it  .