Cisco Phone Proxy

Unanswered Question
Feb 14th, 2012
User Badges:
  • Blue, 1500 points or more


For the phone-proxy to works properly does i need to put a certificate on the IP Phones?

The Locally Significant Certificate must be manually installed on the IP Phone. Installing the LSC requires the use of at least two USB eTokens and the CTL Client. The CTL Client is used to generate the necessary certificates on the CallManager. Once the CTL Provider and CAPF Services are activated on the cluster, the CTL Client can be run to generate the CTL file on the CallManager. Once this process completes it is then possible to set the "Certificate Operation" on the IP Phone to "Install/Upgrade" through the CCMAdmin Interface. This process must be used for all 7940/60 and older model IP Phones. Without the USB eToken and the CTL Client there is no way to install LSCs on IP Phones. The Part number for the USB eToken is: KEY-CCM-ADMIN-K9=

Note: Even if LSCs are deployed, the hard phone must first register and authenticate with a MIC since the phone-proxy does NOT allow auto-registration.

Is correct?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Leonardo Tadeu Tue, 02/14/2012 - 11:52
User Badges:
  • Blue, 1500 points or more

Other thing in what models of phone i need to use LSC or MIC?

Joseph Martini Tue, 02/14/2012 - 17:00
User Badges:
  • Cisco Employee,

Yes all phones used with phone proxy require certificates (either a MIC or LSC).  7940/7960 phones are the only ones I know of that do not come with Manufacture Installed Certificates (MICs), so you would have to push a Locally Significant Certificate (LSC) to those phone models.  Anything newer like a 7941/61/70 comes with a MIC so those phones are ready to use with the phone proxy right out of the box if you want to use MICs instead of LSCs for authentication.

You also do not need to have the USB e-tokens to pass LSCs to the phones.  Here's how to do this so you don't have to purchase the e-tokens:  Note that if you want to encrypt phones or pass LSCs to phones without locally (not behind an ASA) you would need the USB e-tokens.


This Discussion