MIC,LSC, Security Endpoints

Regarding security endpoints, you have 2 opportunities :

  • Newer phones are using more an existing Mafufacturing Installed Certificate , this is the MIC
  • Meanwhile , old phones will use a Locally Significant Certificate ( LSC) which will be installed by the Certificate Authority Proxy Function (CAPF)

As LSC must be a transaction between the Ip phone and the CAPF , here is the process as it is issued :

  1. IP Phone generates a public/private key pair
  2. A TLS Session is established with the CAPF Service and the keys and identity are sent from the phone to CAPF
  3. The CAPF Service creates and sends an LSC to the phone
  4. The IP Phone installs the LSC

Also for info, the CAPF Service must be in the phone CTL file , which is downloaded from the TFTP when the phone boots .

SCCP/Skinny Transport Layer

As defined for SIP , here are the transport layers used by Skinny/SCCP Protocol:

  • TCP Connection with CUCM
  • UDP Connection between the endpoints

SCCP is a Cisco proprietary protocol master/slave protocol that Call Manager and other call agents can use to communicate with devices and endpoints as Cisco IP Phones.
SCCP uses port TCP/2000 and TCP/2443 for SCCPS