CUBE - TLS

We need to create a CSR which will be signed by a CA (and likely also an intermediate CA). Steps:

  • Create trustpoint 'CUBETLS2' (we could call it anything) as per below config
    • crypto pki trustpoint CUBETLS2
        enrollment terminal pem
        serial-number none
        ip-address none
        subject-name cn=ROUTER1.mydomain.com
        subject-alt-name ROUTER1.mydomain.com
        revocation-check none
        resakeypair CUBETLS2
        hash sha512
  • Request the CSR
    • ! This displays the Certificate Signing Request (CSR) to the terminal
      configure terminal
        crypto pki enroll CUBETLS2
      !

Then once you have the PEM file returned - which should contain the signed cert, as well as the inter and root CAs) you need to import the intermediate and CA certs (in that order and both together)

  • conf terminal
      crypto pki authenticate CUBETLS2
  • Paste the 2 certs into above. Each Cert will start and end with —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—–
  • You will paste both the inter and CA cert (in that order) and then after pasting in each leave a line space to complete the import.

Finally import the actual certificate for that router.

  •  
    crypt pki import CUBETLS2 certificate

What we want - TLS between CUBE and CUCM - but not have SRTP - Note enabling SRTP can have a 75% impact on sizing on the 4431s)

Reference: https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html

  • Make sure CUBE and CUCM are both NTP synced, i.e. their times are correct.
  • Enabling SIP over TLS requires the CUBE to have a Security License as well as the UC License
  • Import CallManager Cert (note: not the Tomcat cert) for each CUCM Node you are sending / receiving calls from the CUBE
    • Note - you could get CallManager Certs signed by CA - meaning only the CA cert should need to be imported - but usually means you have to redo certs every 2 years. Self Signed Certs last 5 years. See this guide
  • Create a Cert for the CUBE and export, then import into CUCM as a CallManager-Trust Certificate - with a Subject and a CN equal to the routers FQDN, e.g. cubeA.mydomain.com
  • CUCM - Create a 'encrypted' Security Profile (see example) for each CUBE for and set the subject line in it to be the FQDN of the CUBE and assign to the SIP trunk. Set the SIP Trunk Destination IP address of the CUBE and set the port as 5061
  • Enable SIP Option Pings - with a SIP profile
  • Create a SIP Options Profile with tls and assign to the Outbound Going CUCM dial-peer
  • Set the incoming and outgoing CUCM Dial-peers with session transport tcp tls
  • Same Details Steps and example config extracts below

CUBE Config

Create Trustpoint for self signed CUBE certificate
CUBE-A(config)#crypto pki trustpoint CUBE-A.mydomain.com
CUBE-A(ca-trustpoint)# enrollment selfsigned
CUBE-A(ca-trustpoint)# serial-number none
CUBE-A(ca-trustpoint)# fqdn none
CUBE-A(ca-trustpoint)# ip-address none
CUBE-A(ca-trustpoint)# revocation-check none
CUBE-A(ca-trustpoint)# subject-name cn=CUBE-A.mydomain.com
CUBE-A(ca-trustpoint)# rsakeypair CUBE-A.mydomain.com

Create the certificate for the CUBE

CUBE-A(config)#crypto pki enroll CUBE-A.mydomain.com
% The fully-qualified domain name will not be included in the certificate
Generate Self Signed Router Certificate? [yes/no]: yes

Router Self Signed Certificate successfully created

CUBE-A(config)#

Export the Self Signed Certificate

  • Copy the output between the —–BEGIN CERTIFICATE—- and —-END CERTIFICATE—- into a text file and save as a .cer file.
CUBE-A(config)#crypto pki export CUBE-A.mydomain.com pem terminal
% Self-signed CA certificate:
-----BEGIN CERTIFICATE-----
MIICNDCCAZ2gAwIBAgIBATANBgkqhkiG9w0BAQUFADAjMSEwHwYDVQQDExhDVUJF
LlhakjhmAgMBAAGjeDB2MA8GA1UdEwEB/MAgMBAAGjeDB2MA8GA1UdEwEB/xMDAw
MDAwWjAjMSEwHwYDVQQDExhDVUJFLUEudmhpaGVhbHRoY2FyZS5uZXQwgZ8wDQYJ
KoZIhvcNABaNanaQgY0AMIGJAoGBALF79FOfyGAHaJgRuhehzSFX6/Gop8/vwGuq
TOxWLySHaZ/5NpD4K67DoZJriDAfBC/j1KLkF6YK9LeFvEGkvgc0y/PjZx3/wMTj
k059THE0CNvvMCxZY66NXvsWlBajX1dhcd6LdevPSPe8UpR/hmdF0Iyuy3HTzKzk
r7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEB/wQFMAMBAf8wIwYDVR0RBBwwGoIYQ1VC
RS1BLnZoaWhlYWx0aGNhcmUubmV0MB8GA1UdIwQYMBaAFJDTla2gcpXY2D0OQ7Tk
a2gcpXY2D0OQTANBgkqhkiG9w0Br7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEBIyuJv
AQUFAAOBgQAgSpp2KdMoraJLhDPqMxJG+WJFMVeM4PXI8AcnjAPvvT72vXZu1hx7
G98QZjaCPCImJNnJAYJuQ2Ivp5IQ0EJv0AynGEwISX0cZ+8GBVe1qF7j2Dpsw8pb
izDlGeJ5yx2mxi2AyndVhnXfpU6b2GKMz46FmzZfSeqW3QUzTLNM7w==
-----END CERTIFICATE-----

% General Purpose Certificate:
-----BEGIN CERTIFICATE-----
MIICNDCCAZ2gAwIBAgIBATANBgkqhkiG9w0BAQUFADAjMSEwHwYDVQQDExhDVUJF
LlhakjhmAgMBAAGjeDB2MA8GA1UdEwEB/MAgMBAAGjeDB2MA8GA1UdEwEB/xMDAw
MDAwWjAjMSEwHwYDVQQDExhDVUJFLUEudmhpaGVhbHRoY2FyZS5uZXQwgZ8wDQYJ
KoZIhvcNABaNanaQgY0AMIGJAoGBALF79FOfyGAHaJgRuhehzSFX6/Gop8/vwGuq
TOxWLySHaZ/5NpD4K67DoZJriDAfBC/j1KLkF6YK9LeFvEGkvgc0y/PjZx3/wMTj
k059THE0CNvvMCxZY66NXvsWlBajX1dhcd6LdevPSPe8UpR/hmdF0Iyuy3HTzKzk
r7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEB/wQFMAMBAf8wIwYDVR0RBBwwGoIYQ1VC
RS1BLnZoaWhlYWx0aGNhcmUubmV0MB8GA1UdIwQYMBaAFJDTla2gcpXY2D0OQ7Tk
a2gcpXY2D0OQTANBgkqhkiG9w0Br7qkdc3JAgMBAAGjeDB2MA8GA1UdEwEBIyuJv
AQUFAAOBgQAgSpp2KdMoraJLhDPqMxJG+WJFMVeM4PXI8AcnjAPvvT72vXZu1hx7
G98QZjaCPCImJNnJAYJuQ2Ivp5IQ0EJv0AynGEwISX0cZ+8GBVe1qF7j2Dpsw8pb
izDlGeJ5yx2mxi2AyndVhnXfpU6b2GKMz46FmzZfSeqW3QUzTLNM7w==
-----END CERTIFICATE-----

CUBE-A(config)#

Import all CallManager Nodes Certs onto the CUBE which will send or receive calls

  • Download the Callmanager cert (not tomcat certs) from each CUCM node which you are sending / receiving calls from.
  • Note the expiry date of the certs (5 years from first created) - if necessary regenerate certs in advance so certs last for 5 years - note - this is service impacting as requires restarting of services - see above notes

Example below for one CUCM Node

  • Create trustpoint
Enter configuration commands, one per line.  End with CNTL/Z.
CUBE-A(config)#crypto pki trustpoint uc-cucm-sub-1a.mydomain.com
CUBE-A(ca-trustpoint)# enrollment terminal
CUBE-A(ca-trustpoint)# revocation-check none
  • Import Certificate
CUBE-A(config)#crypto pki authenticate uc-cucm-sub-1a.mydomain.com

Enter the base 64 encoded CA certificate.
End with a blank line or the word "quit" on a line by itself

-----BEGIN CERTIFICATE-----
MIID0TCCArmgAwIBAgIQWgh0k4uyHCX1X6MzuUVPJDANBgkqhkiG9w0BAQsFADB9
MQswCQYDVQQGEwJJRTEMMAoGA1UECgwDVkhJMREwDwYDVQQLDAhUZWxlY29tczEp
MCcGA1UEAwwgVUMtQ1VDTS1TVUItMUEudmhpaGVhbHRoY2FyZS5uZXQxETAPBgNV
BAgMCExlaW5zdGVyMQ8wDQYDVQQHDAZEdWJsaW4wHhcNMTYwODA4MTUxNDAzWhcN
MjEwODA3MTUxNDAyWjB9MQswCQYDVQQGEwJJRTEMMAoGA1UECgwDVkhJMREwDwYD
Vbott0mbAnNaBaNaNasB00PBo5sEAwwgVUMtQ1VDTS1TVUItMUEudmhpaGVhbHRo
Y2FyZS5uZXQxETAPBgNVBAgMCExlaW5zdGVyMQ8wDQYDVQQHDAZEdWJsaW4wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCzXdBYGES6JwDXXtlNPLh3TI8L
spH0+pA7Zc5GdjSTUNGqcLqNI+bOD8iynIo2wXyaK8D30qkP4H58uGHZqeWUUBTD
ZX/mei7fNKpXn0PfNUaj/ne8DhovIJnI1jrtBcV6zsxW7LRnew2yuXhZ13+LlpS5
se6hdnXcYSnh5hQcIuMRTU/E6B+OI2Xkd2W9SmeznJGwXvYYJwRT7yo8i5WYHb/b
mXzIzeW41gc23vkyU5dNeDwUNfets8vNAN9PwM6559jSCGQgX20WetnlQn5NHk25
SQh3XoAZdIy3ZQFFkEYIAE6DhNjkKeqATC6kuLVSWVm4mosu8pT6Mlp+L9XzAgMB
AAGjTTBLMAsGA1UdDwQEAwICtDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUH
AwIwHQYDVR0OBBYEFJm6E+cGQACVadgUvdqneg5n++3PMA0GCSqGSIb3DQEBCwUA
A4IBAQCzU/OjoZGYBOPULf4OkxW3bOmI5zhpbXm3BWCo20QeIfTPaM/v85n5eYN9
BBNlawztvottcR7YH4yhz5wMn5ICPWiqacEumIfoxnz9v7hQeSDpgJ0MoMHarFgB
ThPuDsPZQV5qK73KIm0DNNcbFO1G1OiEcXenKqEIhnSvPxRZD8KZOWlc2OhWhPLk
l6MOzMzEcQRDdMY5TpoWj4OBtrGIRFbJ1IfDb3AtMKyxkQF4lLvUy7K8skjymr8H
qL6hJqkwlsCPiVu6Oi4Q9Y85kl8m3MwA6f367rc2k+iIPAt3h7QwldgC2d5VJFJk
hawnxjo0viK5yXidux79c/fu++3r
-----END CERTIFICATE-----

Certificate has the following attributes:
       Fingerprint MD5: FFA5B2F6 7058E607 AAE0F1BC 8D1C1972
      Fingerprint SHA1: B7332EB9 1EB2BEDB 9F7B1963 7A219D1D BE5F4125

% Do you accept this certificate? [yes/no]: yes
Trustpoint CA certificate accepted.
% Certificate successfully imported

Enable Security License

Note: Make sure you are entitled to have a security license on the CUBE - if not purchase one. This command requires the CUBE to be reloaded to take effect.

CUBE-A(config)#license boot level securityk9
% use 'write' command to make license boot config take effect on next boot

CUBE-A(config)#
CUBE-A#wr

Configure SIP to use the Trustpoint Self Signed Certificate

CUBE-A(config)#sip-ua
CUBE-A(config-sip-ua)#crypto signaling default trustpoint CUBE-A.mydomain.com

Configure a TLS SIP Options Profile

!
voice class sip-options-keepalive 3
 description ### TLS SIP options PING ###
 down-interval 10
 up-interval 10
 retry 3
 transport tcp tls
!

Update Dial-peers to/from CUCM

  • to use TLS (the 'session transport' command)
  • to use the new SIP options over TLS profile '3' - configured above
dial-peer voice 2500 voip
 description ### to CUCM ###
 translation-profile outgoing CUCM
 huntstop
 destination-pattern +3530000000000
 session protocol sipv2
 session transport tcp tls
 session server-group 2000
 voice-class codec 1
 voice-class sip options-keepalive profile 3
 voice-class sip bind control source-interface GigabitEthernet0/0/2
 voice-class sip bind media source-interface GigabitEthernet0/0/2
 dtmf-relay rtp-nte
 no vad
!
dial-peer voice 9500 voip
 description ### from CUCM ###
 session protocol sipv2
 session transport tcp tls
 destination dpg 9000
 incoming uri via CUCM
 voice-class codec 1
 voice-class sip early-offer forced
 voice-class sip bind control source-interface GigabitEthernet0/0/2
 voice-class sip bind media source-interface GigabitEthernet0/0/2
 dtmf-relay rtp-nte
 no vad

Upload CUBE Self Signed Cert to CUCM

Make sure to upload as a CallManager-Trust Certificate - as per below screenshot.

The GUI informs you to restart the CUCM Service after uploading this certificate, but you do not need in this case

Create SIP Security Profile for each CUBE

  • The Subject on the certificate must match what is detailed here.

Update CUCM SIP Trunk

  • Edit the SIP trunk to make the destination Port 5061 (instead of 5060).
  • Assign the Dedicated CUBE Security profile configured in previous step
  • Recommend you configure a SIP Profile which includes SIP options PINGs (I would recommend for all SIP Trunks).
  • Reset the SIP Trunk (and I found I had to reset the Security Profile).
debug crypto pki api
debug crypto pki callbacks
debug crypto pki messages
debug crypto pki transactions
debug ssl openssl errors
debug ssl openssl msg
debug ssl openssl states
debug ip tcp transactions
debug ccsip verbose

After regeneration of CallManager Certs

  • Restart Cisco Callmanager Service and other relevant services including Cisco CTI Manager for the regenerated certificates to become active.
  • When regenerating on TFTP Servers - see above Cisco link
    • Stop TFTP A Service,
    • Regenerate TFTP A Cert,
    • Reset phones (so they use B side TFTP)
    • Restart CUCM Services & CTI
    • Restart TFTP A Service
    • Repeat on B side
  • vendors/cisco/uc/cube/tls.txt
  • Last modified: 2026/05/19 17:50
  • by gerardorourke