cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1670
Views
0
Helpful
14
Replies

TLS CUCM 11.5

Gilles Guillerm
Level 1
Level 1

Hello,

 

I try to change the TLS version of the CUCM 11.5, but when I go to the CLI and tape "show tls min-version" or "set tls min-version" it is like the command does not exist.

Is this normal ? How can I change the TLS version ?

 

Thanks

Best regards

Gilles

 

14 Replies 14

Jaime Valencia
Cisco Employee
Cisco Employee

Are you running the restricted or unrestricted version?

HTH

java

if this helps, please rate

I don't know what you mean with "restricted version"....it is a CUCM hosted on a BE-6000-S for a small compagny. Licenses are OK.

How can I know if it is a restricted version ?

Thanks

Log to CCMAdmin, do you see unrestricted or something along those lines mentioned in there?

HTH

java

if this helps, please rate

Hi there, 

Once you logged in to the Cisco call manager administration you find nothing related to restricted or unrestricted if it is restricted version. but it definitely mentions as unrestricted if it one. restricted_0.png

 

Unrestricted

unrestricted_1.png

 

reference - Identify whether current CUCM version is the export restricted or unrestricted version

 

******Rate useful posts. ********

 

The version should be in "restricted version" because the voice and signaling are secured.

OK, are you running a CUCM version which does enable that feature?

And using an account with the right privilege level for that command?

HTH

java

if this helps, please rate

For now, there is only one admin account to connect to the CUCM CLI. So I think I have the privilege for that command (I can restart the CUCM).
The cucm is in mixted mode for secure voice and signaling. version is 11.5.1
I'll answer you more efficiently on tuesday....because now I'am on holliday for few days.

tc4679
Level 1
Level 1

ahhh I remember Mr Jaime Valencia doing a very good video on TLS and Call Manager approx 12months ago, although i cannot find it now, have you still got your video series running Jaime?

YT disabled my account, and thus my channel, since last November, working to try to get them back online in a new site within Cisco's domain.

HTH

java

if this helps, please rate

Hi,
I have checked the CUCM and it is a restricted version and my account for CLI is the admin account...on CLI no posibility do have "show tls min-version" or "set tls min-version"

I have found this on the cisco bug site : Allow TLS versions to be disabled on CUCM : CSCvd93544
Symptom:
Currently, CUCM allows TLS versions 1.0, 1.1, and 1.2. To disable a TLS version on CUCM, you must enable FIPS mode and regenerate certificates.
This is a feature request to allow CUCM to be configured to reject connections that use TLS versions 1.0 and 1.1.


=> it seems to be my problem.....

What is the exact CUCM release you're running?

HTH

java

if this helps, please rate

it is like .... 11.5.1.0000xx (I couln't give you the exact release, but it is a version whixh was installed on january 2017)
I think it is one of the first CUCM 11.5.1 version
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: