CUCM Configuration
These are the basic configurations in CUCM:
After configuring CUCM, you will configure the OneAlert Cisco Notifier to add the call manager. By default, the CUCM administrator account is used, but you can designate a different user account. Whatever account you use must have these roles assigned:
- Standard AXL API Access
- Standard CCM Admin Users
- Standard SERVICEABILITY Administration
- Log into the CUCM Administration page
-
Go to User Management > User Settings > Access Control Group
- Select Add New. For Name, enter OneAlert AXL Users and select Save.
- For Related Links (in the upper right), select Assign Role to Access Control Group and select Go.

-
Enable the following roles:
- Standard AXL API Access
- Standard CCM Admin Users
- Standard SERVICEABILITY Administration for Cisco Call Manager Serviceability > Administer All Aspects of Serviceability System
- Select Save.
These instructions are for creating a new user account, but you can edit an existing one.
- Go to User Management > Application User and select Add New.
- Enter a User ID and Password.
-
Under Permissions Information, select Add to Access Control Group
- Enable OneAlert AXL Users, which is the user group you just created.
- Select Add Selected.
- Verify all information is correct and select Save.
- Go to System > Enterprise Parameters and scroll to Secure Phone URL Parameters.
-
Populate the URL Authentication and Secured Authentication URL fields as follows:
http://<server_ip>:<authenticator_port>/Authenticator/Authenticate
http://10.10.10.10:8008/Authenticator/Authenticate
- Save your changes.
- Reboot your phones.
Note: This can also be done as bulk administration. See Enable Web Access via Bulk Administration.
- Go to Device > Phone.
-
Search for the phone that is not working. Select the Device name in the search result list.
To search by model number, change Find Phone where to Device Type contains, enter the model number, and select Find.
- Go to Product Specific Configuration Layout at the bottom of the page.
-
Set Web Access to Enabled.
Tip: This field defaults to Disabled for some phone models.
- Save your changes.
Important: The following instructions are outside the scope of Support. Use of these instructions is left to the discretion of the customer.
This change requires phones to be reset. Consider scheduling this change during a maintenance window. You will need to search by Device Type. Searching for more than one phone model will not allow the Web Access option to be displayed.
- Go to Bulk Administration > Phones > Update Phones > Query.
- Change Find Phones Where to Device Type.
- Search for the desired phone model and click Next.
-
Do one of the following:
- Select Reset Phones, if the phone is NOT currently in use.
- Select Don't Reset/Restart phones/Apply Config, if the phone IS in use.
- Enable Web Access.
- Select Enabled.
- Select Run Immediately.
- Select Submit.
- Repeat this process to change additional phone models.
- Go to System > Enterprise Phone Configuration.
- Set HTTPS Server to http and https Enabled.
- Set Web Access to Enabled.
- Save changes.
- Go to Device > Device Settings > Common Phone Profile.
- Select Find in the search parameters.
- Select Shared Common Phone Profile.
- Under Product Specific Configuration Layout, set Web Access to Enabled.
- Click Save > Apply Config or Save > Reset.
There are two paths:
Use the self-signed certification created during the OneAlert installation.
A self-signed certificate was created during OneAlert installation. You need to export it and upload it to CUCM.
- Open the IIS Manager on the IIS server hosting the OneAlert application.
- Select the server name in the left-navigation tree.
- Double-click Server Certificates.

- Double-click the certificate issued to your OneAlert server.
- Go to the Details tab.
- Select Copy to File.
- The Welcome to the Certificate Export Wizard opens. Select Next.
- Select Do not export the private key and select Next.
- Select Use Base-64 encoded X.509 (.CER) and select Next.
- Browse to an export location and provide a descriptive name. Select Next.
- Select Finish to export the certificate.
- Proceed to Upload Certificate to CUCM below.
If your organization requires a certificate assigned by a Certificate Authority, follow the Optional TLS/SSL Setup instructions in the Installation topic on how to create a certificate request.
You must use one of the following as the Common name:
- server host name if your OneAlert server is standalone
- FQDN if your OneAlert server is a member of a domain
Once you've been notified that your signed certificate is available, download it from your Certificate Authority so you can upload it to your Call Manager.
There are three basic steps:
- Change the CUCM Navigation to Cisco Unified OS Administration and select Go.
- Log in to your CUCM.
(Hint: This is typically a different login than CM Administration.) - Select Security > Cert Management.
- Select Find and check that the certificate has not already been uploaded.
- Select Upload Certificate/Cert chain.
- Select tomcat-trust from the Certificate Purpose drop-down list.
- Provide a Description of your choice, for example RevApp. (Do not use spaces in the name.)
- Select Choose File and select your certificate.
- Select Upload.
- Change the CUCM Navigation to Cisco Unified Serviceability and select Go.
- Select Tools > Control Center - Network Services.
- Scroll to the bottom of the screen to Security Services and select Cisco Trust Verification Service.
- Select Restart.
- Log in to OneAlert.
- Go to Configuration > Phone Systems > Cisco.
- Select Settings.
- Scroll to the bottom of the page and select Use SSL/TLS.
- Select Save.
- In OneAlert, go to Status > System Status.
- Expand Cisco Notifier and select Restart.
This section is optional.
Configure HTTPS Authentication URL in CUCM
- Go to System > Enterprise Parameters and scroll down to the Secured Phone URL Parameters section.
-
Populate the Secured Authentication URL fields as follows:
https://<Revolution_server_ip>/Authenticator/Authenticate
for example:
https://10.10.10.10/Authenticator/Authenticate
- Save your changes.
- Reboot your phones.
Note: You won't see the certificate listed in Cisco Notifier.
Your Cisco phones now trust OneAlert.
If your phones are receiving notification audio but not text and image, the phone may not be able to verify the certificate.
First, reboot the phone.
If this doesn't resolve the issue, delete the ITL file from the phone and reboot the phone again. Deleting the ITL file forces the phone to refresh its data. (The process for deleting the ITL file is different for different Cisco phone models. Consult your phone model documentation for instructions.)
You can also check you phone logs for errors verifying the certificate.
It is not required for you to set these configurations but can be very useful for including in your notifications.
You include geolocation information in your notifications by using the {cisco.Geolocation} variable in the Title or Body fields. OneAlert pulls this information from your CUCM configuration and presents it in the following order:
-
Name of Business or Resident (if populated), otherwise Name.
-
Numeric House Number
-
House Number Suffix (if populated)
-
Leading Street Direction (if populated)
-
Street
-
Address Suffix
-
Trailing Street Suffix (if populated)
-
City or Township
-
State, Region or Province
-
Zip or Postal Code
-
Landmark (if populated)
-
Floor, prepended with Fl: (if populated)
-
Additional Location Information, prepended with Rm: (if populated)
For example:
Company Name ( 12345 SW Main Street, Portland, OR 97205 Fl:4 Rm: Suite 120 )
Important: SIP Activator is required in order to trigger live broadcast/paging notifications.
Configure a SIP Trunk and SIP line range in CUCM if you're using OneAlert SIP Activator. See Cisco SIP Trunk Setup.
Configure the Cisco Notifier.