there is no CAPF entry in the ITL file. Verify that the CAPF service was activated, and then restart the
TFTP Service. Verify that the ITL file contains a CAPF certificate after the restart, reset the phone to pick
up the latest ITL file, and then retry your certificate operation. If the CAPF server entry in the phone's
security settings menu displays as hostname or fully qualified domain name, confirm the phone is able to
resolve the entry to an IP address.
LSC: Connection Failed
The LSC fails to install. The phone’s Status Messages show "LSC: Connection Failed". This can indicate
one of these conditions:
A mismatch between the CAPF certificate in ITL file and the current certificate, the CAPF service is
in use.
•
The CAPF service is stopped or deactivated.
•
The phone cannot reach the CAPF service over the network.
•
Verify the CAPF service is activated, restart the CAPF service, restart TFTP services where started, reset the
phone to pick up the latest ITL file, and then retry your certificate operation. If the problem persists, take a
packet capture from the phone and the CUCM Publisher, and analyze in order to see if there is bidirectional
communication on port 3804, the default CAPF service port. If not, there can be a network issue.
LSC: Failed
The LSC fails to install. The phone’s Status Messages show "LSC: Failed". The Phone Configuration web
page shows "Certificate Operation Status: Upgrade Failed: User Initiated Request Late/Timedout". This
indicates that the Operation Completes By time and date have expired or are in the past. Enter a date and
time that is at least one hour into the future, and then retry your certificate operation.
LSC: Operation Pending
The LSC fails to install. The phone's Status Messages show "LSC: Connection Failed". The phone
Configuration page shows "Certificate Operation Status: Operation Pending". There are different reasons
that one can see the Certificate Operation Status: Operation Pending status. Some of them include:
ITL on the phone is different than the one currently used on the configured TFTP servers.
•
Issues with corrupt ITL's. When this happens, devices lose their trusted status and the command utils
itl reset localkey needs to be run from the CUCM Publisher to force the phones to now use the
ITLRecovery certificate. If the cluster is in mixed-mode, you need to use the command utils ctl reset
localkey. Next, you see an example of what you can see when you attempt to view a corrupt ITL from
the CLI of CUCM. If there is an error when you try to view the ITL and attempt to run the utils itl
reset localkey command, but you see the second error, this can be a defect Cisco bug
ID CSCus33755. Confirm if the version of the CUCM is affected.
•