You'll want the CallManager.pem of each node as a CallManager-Trust on all servers on all clusters to ensure you can move back and forth. TVS should then take care of the rest.
You can use the Bulk Certificate Export/Consolidate/Import process to do this a little more automagically. Make sure to do the consolidate on the newer version cluster. On Mon, Aug 7, 2017 at 2:53 PM, Mike O <[email protected]> wrote: > Ryan, > > > If I export the CallManager.pem from the new cluster and import to the > old cluster. I can then just change option 150 on the DHCP server to the > new cluster and reset? Won't that over write the existing CallManager.pem? > I need to verify that the phones are indeed connecting to the TVS on the > old cluster, but I don't see any reason why they aren't connecting to the > TVS. > > > Thanks, > > Mike > > > ------------------------------ > *From:* Ryan Ratliff (rratliff) <[email protected]> > *Sent:* Sunday, August 6, 2017 9:53 AM > *To:* Schlotterer, Tommy; Mike O > *Cc:* cisco-voip voyp list > *Subject:* Re: [cisco-voip] CUCM 10.5 cluster migration > > Corporate Directory will work with the default settings in 10.4.2, secure > EM will not. > > If both clusters are up and running you are much better off just adding > CallManager.pem from the TFTP server of the new cluster to Certificate > Management of the old cluster as "Phone-sast-trust”. > This will let TVS on the old cluster authenticate the new cluster’s ITL > and you don’t need to mess with anything. > > It does require that the phones can establish a secure connection to TVS > on the old cluster, but if they can’t do that already then they wouldn’t > take the rollback parameter change either. > > -Ryan > > On Aug 3, 2017, at 2:03 PM, Schlotterer, Tommy <[email protected]> > wrote: > > They will register and work, but no SSL functions will work, eg secure > Extension mobility or the corporate directory. > > Tommy > > > > Tommy Schlotterer | Systems Engineer - Collaboration > Presidio (NASDAQ: PSDO) | www.presidio.com > 20 N Saint Clair 3rd Floor, Toledo, OH 43604 > D: 419.214.1415 <(419)%20214-1415> | C: 419.706.0259 <(419)%20706-0259> | > [email protected] > > > > [image: Future. Built.] <http://www.presidio.com/> > > > Follow us: > > [image: Follow Presidio on Twitter] <http://www.twitter.com/presidio> > > > > *From:* cisco-voip [mailto:[email protected] > <[email protected]>] *On Behalf Of *Mike O > *Sent:* Thursday, August 03, 2017 1:52 PM > *To:* [email protected] > *Subject:* [cisco-voip] CUCM 10.5 cluster migration > > Hi All, I need to move about a 100 phones to a new cluster, and then add > an additional 200+ phones. My problem is I want to use the "Prepare Cluster > for Rollback to pre-8.0" parameter, but I can't change the option 150 in > the DHCP server until the next day. My question is once I set this > parameter and I reset the phones they will register with an empty ITL > file, but will the phones still function? If I can reset the phones to > clear the existing ITL and have them work the following day I can then > change the option 150 to the new cluster and then reset the existing phones > and add new phones in. I know I can lab this up, but wanted to make sure > there were no gotchas associated with this method. > > Thanks, > Mike > > > > *This message w/attachments (message) is intended solely for the use of > the intended recipient(s) and may contain information that is privileged, > confidential or proprietary. If you are not an intended recipient, please > notify the sender, and then please delete and destroy all copies and > attachments. Please be advised that any review or dissemination of, or the > taking of any action in reliance on, the information contained in or > attached to this message is prohibited.* > > _______________________________________________ > cisco-voip mailing list > [email protected] > https://puck.nether.net/mailman/listinfo/cisco-voip > > > _______________________________________________ > cisco-voip mailing list > [email protected] > https://puck.nether.net/mailman/listinfo/cisco-voip > >
_______________________________________________ cisco-voip mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-voip
