For everyone that's interested. I verified the behavior with Phone Console logs and TVS traces.
The phone contacts TVS and requests it to verify the signer of the CTL (in that case e-token).
TVS is able to find the e-token (signer) in CUCM with a Role = 0 (meaning SAST).
I haven't found the exact location of where CUCM stores these e-tokens. Yet we can conclude that CUCM is able to verify the signer even tough these e-tokens don't show up on the OS GUI.
If anyone knows where they reside, I would be happy to find out.
Thank you.