Reset Phones
Make sure that you reset your phones after you complete all your encrypted TFTP configuration file updates.
Procedure
Step 1
From Cisco Unified CM Administration, choose Device > Phones.
Step 2
Click Find.
Step 3
Click Select All.
Step 4
Click Reset Selected.
Disable TFTP Encrypted Configuration Files
If digest authentication is True for the phone that is running SIP when the TFTP encrypted configuration
setting is False, digest credentials may get sent in the clear.
Warning
After you update the setting, the encryption keys for the phone remain in the Unified Communications
Managerdatabase.
Cisco Unified IP Phones 7911G, 7931G (SCCP only), 7941G, 7941G-GE, 7942G, 7945G, 7961G, 7961G-GE,
7962G, 7965G, 7971G, 7971G-GE, and 7975G request an encrypted file (.enc.sgn file) when the encrypted
configuration setting gets updated to False, the phone requests an unencrypted, signed file (.sgn file).
If Cisco Unified IP Phones are running on SCCP and SIP, request an encrypted file when the encryption
configuration setting gets updated to False. Remove the symmetric key from the phone GUI so that the phone
requests an unencrypted configuration file the next time that it is reset.
• Cisco Unified IP Phones running on SCCP: 6901, 6911, 6921, 6941, 6945, 6961, 7906G, 7911G, 7921G,
7925G, 7925G-EX, 7926G, 7931G, 7941G, 7941G-GE, 7942G, 7945G, 7961G, 7961G-GE, 7962G,
7965G, 7971G, 7971G-GE, 7975G, 8941, 8945.
• Cisco Unified IP Phones running on SIP: 6901, 6911, 6921, 6941, 6945, 6961, 7906G, 7911G, 7941G,
7941G-GE, 7942G, 7961G, 7961G-GE,7962G, 7965G, 7970G, 7971G, 7971G-GE, 7975G, 8941, 8945,
8961, 9971, 7811, 78321, 7841, 7861, 7832, 8811, 8841, 8845, 8851, 8851NR, 8861, 8865, 8865NE,
8821, 8831, 8832, 8832NR.
Procedure
Purpose
Command or Action
To disable encryption for the phone configuration files,
Uncheck TFTP Encrypted Config check box in the phone
security profile associated to the phone.
Step 1
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs
110
Basic System Security
Reset Phones