To obtain a signed certificate, an IP phone needs to enroll with the entity that will issue (sign) the certificate. During enrollment, the phone will get the certificate of the issuer and then send its data to the issuer asking for a (signed) certificate. IP phone enrollment depends on the type of certificate.
With MICs, enrollment was already done by Cisco manufacturing during production. When the IP phone is shipped to the customer, it already has its public and private keys, a certificate issued by the Cisco manufacturing CA, and the certificate of the Cisco manufacturing CA installed. No other PKI provisioning tasks are required. MICs always remain on the phone, even if an LSC is added.
With LSCs, enrollment has to be done by the customer.
Note
If the IP phone has both a MIC and an LSC, the LSC has priority.
CAPF Acting as a CA
To obtain an LSC from the CAPF acting as a CA, an IP phone has to enroll with the CAPF, as shown in Figure 26-9.
Figure 26-9. CAPF Enrollment Process
The CAPF enrollment process is as follows:
CAPF Acting as a Proxy to an External CA
If an IP phone should obtain an LSC from an external CA using the CAPF as a proxy, the IP phone has to enroll with the external CA, as shown in Figure 26-10.
Figure 26-10. CAPF External CA Enrollment Process
The external CA enrollment process occurs as follows:
Part I: Cisco CallManager Fundamentals
Introduction to Cisco Unified Communications and Cisco Unified CallManager
Cisco Unified CallManager Clustering and Deployment Options
Cisco Unified CallManager Installation and Upgrades
Part II: IPT Devices and Users
Cisco IP Phones and Other User Devices
Configuring Cisco Unified CallManager to Support IP Phones
Cisco IP Telephony Users
Cisco Bulk Administration Tool
Part III: IPT Network Integration and Route Plan
Cisco Catalyst Switches
Configuring Cisco Gateways and Trunks
Cisco Unified CallManager Route Plan Basics
Cisco Unified CallManager Advanced Route Plans
Configuring Hunt Groups and Call Coverage
Implementing Telephony Call Restrictions and Control
Implementing Multiple-Site Deployments
Part IV: VoIP Features
Media Resources
Configuring User Features, Part 1
Configuring User Features, Part 2
Configuring Cisco Unified CallManager Attendant Console
Configuring Cisco IP Manager Assistant
Part V: IPT Security
Securing the Windows Operating System
Securing Cisco Unified CallManager Administration
Preventing Toll Fraud
Hardening the IP Phone
Understanding Cryptographic Fundamentals
Understanding the Public Key Infrastructure
Understanding Cisco IP Telephony Authentication and Encryption Fundamentals
Configuring Cisco IP Telephony Authentication and Encryption
Part VI: IP Video
Introducing IP Video Telephony
Configuring Cisco VT Advantage
Part VII: IPT Management
Introducing Database Tools and Cisco Unified CallManager Serviceability
Monitoring Performance
Configuring Alarms and Traces
Configuring CAR
Using Additional Management and Monitoring Tools
Part VIII: Appendix
Appendix A. Answers to Review Questions
Index