We’ve been informed by Cisco that certain security ciphers and algorithms supported with CUCM v12.5 are no longer compatible with CUCM v15. If you’ve recently upgraded to v15 without updating these settings, your data source(s) may stop connecting to our service until the settings have been updated to be compatible with both the CUCM update and our SFTP service.
Below is a list of variables currently confirmed to be supported by ISI’s SFTP service (transfer.isi-info.com) that you can refer to when updating your settings in the
CUCM v15 settings may show no ciphers listed. The fields being blank means it will use the default built-in system ciphers for interfaces like HTTPS and SIP, instead of disabling encryption.
ISI Supported Options #
Ciphers/Encryption Algorithm:
- aes256-ctr
- twofish256-ctr
- aes192-ctr
- twofish192-ctr
- aes128-ctr
- twofish128-ctr
- twofish-ctr
- blowfish-ctr
- 3des-ctr
- aes256-cbc
- twofish256-cbc
- twofish-cbc
- aes128-cbc
- twofish128-cbc
- blowfish-cbc
- 3des-cbc
- cast128-cbc
MAC algorithms:
- hmac-sha3-512
- hmac-sha3-384
- hmac-sha3-256
- hmac-sha3-224
- hmac-sha2-512
- hmac-sha2-384
- hmac-sha2-256
- hmac-sha2-224
- hmac-sha1
- hmac-md5
Kex algorithms:
- diffie-hellman-group14-sha256
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group14-sha1
- diffie-hellman-group-exchange-sha1
- diffie-hellman-group1-sha1
- diffie-hellman-group-exchange-sha512@ssh.com
Additional Information #
External Cisco link for more information: Security Guide for Cisco Unified Communications Manager, Release 15 and SUs