01-08-2025 07:10 AM
Hello ,
Our version is cucm 14 su4 we do not use IPSEC feature , in previos version IPSEC cert. was using for DRF but now DRF is managing by Tomcat so can we delete IPSEC cert. from entire cluster ?
Best Regards ,
01-08-2025 10:18 AM
Where have you seen that DRF don’t use the IPSEC certificate? From what I know it still uses this certificate.
01-08-2025 12:07 PM
Roger maybe I am wrong , but can you explain IPSEC regarding below chart ;
01-08-2025 12:38 PM
What is the number of the breakout season from Live? I rather look at it first hand before I comment.
01-08-2025 10:15 PM - edited 01-08-2025 11:52 PM
As far as I know, from 14 FCS and above, if IPsec is not used, it can be removed. However, I have never deleted them for the customers, and I'm not sure how this can be done. I leave them untouched
01-08-2025 11:43 PM - edited 01-08-2025 11:43 PM
How would one actually remove the IPsec certificate? From what I can see on our system, that runs 15SU3 there is no delete option.
@Nithin Eluvathingal based on the document you shared it looks like DRF (DRS) from version 14SU2 uses the Tomcat-ECDSA certificate.
01-09-2025 12:03 AM
Maybe from CLI ?
set cert delete does not work ?
01-09-2025 01:34 AM
From what I know that is only possible for certificates that are in a trust store named with <something>-trust, for example CallManager-trust or tomcat-trust.
If I run the command from CLI that should from what I understand remove the IPsec cert I get this.
If I list the certificates that the system uses I think that the unit and file names are correctly entered.
01-09-2025 01:13 AM
@Roger Kallberg I'm unsure how it can be deleted even i haven't seen an option to delete it from the GUI, . My understanding, like the OP, is that it can be deleted based on the slides I have seen.
Like the response of a Cisco employee on the community, it could be doable from the CLI. I cannot test this, but if you have the option, please try it and let us know.
https://community.cisco.com/t5/ip-telephony-and-phones/removing-certificates-from-cucm/td-p/2934514
For details on how to delete it and what exactly Cisco meant by this, I guess Cisco TAC could provide an answer.
@extremum ,Keep it untouched or raise a question with TAC if you really want to remove it.
01-08-2025 11:28 PM
I will keep it for now , if someone deleted and experienced please update then I can remove it .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide