/mcpProcedure Step 1 From Cisco Unified Serviceability, choose Tools > Service Activation. Step 2 From the Server drop-down list, select the publisher node and click Go. Step 3 From the Security Services pane, check the services that apply: • Cisco Certificate Enrollment Service—Check this service if you're using an Online CA else leave it unchecked. • Cisco Certificate Authority Proxy Function—Check this service if unchecked (Deactivated). Restart if the service is already activated. Step 4 Click Save if you modified any settings. Step 5 If the Cisco Certificate Authority Proxy Function service was already checked (Activated), restart it: a) From the Related Links drop-down list, select Control Center - Feature Services and click Go. b) From Security Settings pane, check the Cisco Certificate Authority Proxy Function service and click Restart. Step 6 Complete one of the following procedures to configure CAPF settings against individual phones. a) Configure CAPF Settings in a Universal Device Template, on page 78 b) Update CAPF Settings via Bulk Admin, on page 79 c) Configure CAPF Settings for a Phone, on page 80 Configure CAPF Settings in a Universal Device Template Use this procedure to configure CAPF settings to a Universal Device Template. Apply the template against an LDAP directory sync through the feature group template configuration. The CAPF settings in the template apply to all synced devices that use this template. You can only add the Universal Device Template to an LDAP directory that hasn't been synced. If your initial LDAP sync has occurred, use Bulk Administration to update phones. For details, see Update CAPF Settings via Bulk Admin, on page 79. Note Procedure Step 1 From Cisco Unified CM Administration, choose User Management > User/Phone Add > Universal Device Template. Step 2 Do either of the following: • Click Find and Select an existing template. • Click Add New. Step 3 Expand the Certificate Authority Proxy Function (CAPF) Settings area. Step 4 From the Certificate Operation drop-down list, select Install/Upgrade. Step 5 From the Authentication Mode drop-down list menu, select an option for the device to authenticate itself. Security Guide for Cisco Unified Communications Manager, Release 15 and SUs 78 Basic System Security Configure CAPF Settings in a Universal Device Template