<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
The tokenless CTL is signed by the CallManager.pem on the publisher.  Upload that cert as a phone-trust cert and TVS on that cluster will be able to authenticate files signed by that cert.
<div class=""><br class="">
</div>
<div class=""><span class="Apple-tab-span" style="white-space:pre"></span>CTL Record #:1<br class="">
<span class="Apple-tab-span" style="white-space:pre"></span>          ----<br class="">
BYTEPOS<span class="Apple-tab-span" style="white-space:pre"> </span>TAG<span class="Apple-tab-span" style="white-space:pre">
</span>LENGTH<span class="Apple-tab-span" style="white-space:pre"> </span>VALUE<br class="">
-------<span class="Apple-tab-span" style="white-space:pre"> </span>---<span class="Apple-tab-span" style="white-space:pre">
</span>------<span class="Apple-tab-span" style="white-space:pre"> </span>-----<br class="">
1<span class="Apple-tab-span" style="white-space:pre"> </span>RECORDLENGTH<span class="Apple-tab-span" style="white-space:pre">
</span>2<span class="Apple-tab-span" style="white-space:pre"> </span>1701<br class="">
2<span class="Apple-tab-span" style="white-space:pre"> </span>DNSNAME<span class="Apple-tab-span" style="white-space:pre">
</span>20<span class="Apple-tab-span" style="white-space:pre"> </span>videolab-ucm11a-pub<br class="">
3<span class="Apple-tab-span" style="white-space:pre"> </span>SUBJECTNAME<span class="Apple-tab-span" style="white-space:pre">
</span>70<span class="Apple-tab-span" style="white-space:pre"> </span>CN=videolab-ucm11a-pub.videolab.local;OU=TAC;O=Cisco;L=NC;ST=RTP;C=US<br class="">
4<span class="Apple-tab-span" style="white-space:pre"> </span>FUNCTION<span class="Apple-tab-span" style="white-space:pre">
</span>2<span class="Apple-tab-span" style="white-space:pre"> </span>System Administrator Security Token<br class="">
5<span class="Apple-tab-span" style="white-space:pre"> </span>ISSUERNAME<span class="Apple-tab-span" style="white-space:pre">
</span>70<span class="Apple-tab-span" style="white-space:pre"> </span>CN=videolab-ucm11a-pub.videolab.local;OU=TAC;O=Cisco;L=NC;ST=RTP;C=US<br class="">
6<span class="Apple-tab-span" style="white-space:pre"> </span>SERIALNUMBER<span class="Apple-tab-span" style="white-space:pre">
</span>16<span class="Apple-tab-span" style="white-space:pre"> </span><font color="#ff4013" class="">52:0B:74:69:CF:4F:5A:CD:5B:48:6F:EE:99:9E:E0:B8</font><br class="">
7<span class="Apple-tab-span" style="white-space:pre"> </span>PUBLICKEY<span class="Apple-tab-span" style="white-space:pre">
</span>270<span class="Apple-tab-span" style="white-space:pre"> </span><br class="">
8<span class="Apple-tab-span" style="white-space:pre"> </span>SIGNATURE<span class="Apple-tab-span" style="white-space:pre">
</span>256<span class="Apple-tab-span" style="white-space:pre"> </span><br class="">
9<span class="Apple-tab-span" style="white-space:pre"> </span>CERTIFICATE<span class="Apple-tab-span" style="white-space:pre">
</span>961<span class="Apple-tab-span" style="white-space:pre"> </span>76 5D 15 01 0E 41 0D 16 BE EA 8A 98 29 33 EE 27 B6 3E D3 01 (SHA1 Hash HEX)<br class="">
10<span class="Apple-tab-span" style="white-space:pre"> </span>IPADDRESS<span class="Apple-tab-span" style="white-space:pre">
</span>4<span class="Apple-tab-span" style="white-space:pre"> </span><br class="">
This etoken was used to sign the CTL file.<br class="">
<br class="">
<br class="">
</div>
<div class="">admin:show cert own CallManager/CallManager.pem<br class="">
[<br class="">
  Version: V3<br class="">
  Serial Number: <font color="#e32400" class="">520B7469CF4F5ACD5B486FEE999EE0B8</font></div>
<div class="">…</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
<div class="">
<div apple-content-edited="true" class=""> -</div>
<div apple-content-edited="true" class="">Ryan </div>
<br class="">
<div>
<div class="">On Aug 12, 2015, at 9:06 PM, Dave Goodwin <<a href="mailto:Dave.Goodwin@december.net" class="">Dave.Goodwin@december.net</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div dir="ltr" class="">
<div class="gmail_default" style="font-family:tahoma,sans-serif">For anyone who has an environment with multiple mixed mode clusters (CTL file is present), do you know of a way to move devices from one cluster to another?</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif"><br class="">
</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif">Using the eToken SAST (physical USB devices), it seems you can do this by using the same signing token to sign the CTL file on each cluster. With the new tokenless CTL client, it seems each cluster's
 publisher private key is used to sign that cluster's CTL file - so it seems the old way will not work.</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif"><br class="">
</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif">I realize it can be done by deleting the CTL file on the phone (or factory reset) if you're standing in front of it, and I also realize there are commercial software tools that can perform feats
 like this (like UnifiedFX and other competitive offerings). I am looking for a way to do this without either of those methods.</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif"><br class="">
</div>
<div class="gmail_default" style="font-family:tahoma,sans-serif">-Dave</div>
</div>
_______________________________________________<br class="">
cisco-voip mailing list<br class="">
<a href="mailto:cisco-voip@puck.nether.net" class="">cisco-voip@puck.nether.net</a><br class="">
https://puck.nether.net/mailman/listinfo/cisco-voip<br class="">
</div>
</div>
<br class="">
</div>
</div>
</body>
</html>