Hi Jason,
I have tried to downgrade a couple of times to 6.4.6 using the phone user interface. It acts like it will work, but after reboot, the phone software version has not changed. I setup syslog and tried again, but there is not much in the syslog output to indicate what it is doing. I see entries regarding upgrade but there is no information and nothing I could see about it failing.
I tried a different approach that I thought would work. I removed the custom CA certs from the genesys portal. That left only the pure cloud CA certificate which is using device.sec.TLS.customCaCert1. Then I added the customer CA certificates using the device.sec.TLS.customCaCert2 and device.sec.TLS.customCaCert3 in the custom configuration file. I then rebooted the phone and it looks like the TLS handshake works. That is I see Client Hello from the phone, Server Hello followed by Certificate, Key Exchange, Server Hello Done. Previously the phone would send an alert of CA unknown. But this time, it responded with Client Key Exchange, Change Cipher Spec, Encrypted Handshake from the phone. Then New Session Ticket, Change Cipher Spec, Encrypted Handshake from the server. After that, the phone sends an Encrypted Alert so I do not know what the alert says.
In the phone's log it doesn't show much. Is there a log level I can adjust to get more information? I have TLS set to Debug. I did change syslog strict command name validation to 0. But that did not make any difference.
0129145444|log |4|00|SSL post_connection_check failed
0129145444|log |4|00|syslog TLS connect FAILED to (A.B.C.D) port 14680
One other note, is that this phone is configured to send RTCP-XR Publish messages to a collector that is on the same syslog server. It is also configured to use TLS. This seems to work fine. That is, the handshake on that port succeeds and the messages to the collector flow fine. No issue with the TLS connection staying up.
------------------------------
Andrew Klassen
------------------------------
Original Message:
Sent: 01-26-2026 10:15
From: Jason Kleitz
Subject: download custom certificates to phone
Hello Andrew,
I checked internally and there was some discussion that 6.4.7.xxx may not be stable / supported just yet and I don't have access to see how testing has gone. I would recommend trying to downgrade to 6.4.6 and testing again. If that doesn't work, you will need to check with Product Support. If you do open a case with them, please let me know what your case number is.
------------------------------
Jason Kleitz
Online Community Manager/Moderator
Original Message:
Sent: 01-21-2026 16:08
From: Andrew Klassen
Subject: download custom certificates to phone
Hi Jason,
Thanks for the reply. I did try removing and adding the certificate one at a time and that did not work. I am considering installing 6.4.6 but I am a little confused. My phone has 6.4.7.4513 and I can see release notes from Polycom for that release at https://docs.poly.com/bundle/ucs-rn-6-top/page/ucs-6.4.7-rn.html. But for sure that matrix does not show it. So should I "downgrade" from 6.4.7 to 6.4.6? Is it possible that the Genesys Cloud provisioning server hasn't been updated to support this new version so it isn't downloading all the CA certs? Thanks for any advice.
Andrew
------------------------------
Andrew Klassen
Original Message:
Sent: 01-20-2026 13:42
From: Jason Kleitz
Subject: download custom certificates to phone
Hello Andrew,
I can only make a few recommendation. I would first recommend that you try removing all of the certificates and then re-adding them one by one. You may want to run the latest firmware for the VVX 350, which according to Polycom's Software Matrix, shows that 6.4.6 is the latest firmware for the phone.
------------------------------
Jason Kleitz
Online Community Manager/Moderator
Original Message:
Sent: 01-20-2026 10:33
From: Andrew Klassen
Subject: download custom certificates to phone
I need to download two CA certificates to polycom phones. I added the certificates using the admin -> Digital and Telephony -> Telephony -> Certificate Authorities. This means there are now 3 in the list which includes the PureCloud CA certificate. When I reboot the phone, the "Installed custom root CA certificate" list under SSL Certificates on the phone's UI only shows the first two: the PureCloud CA certificate and one of the CA certs I added. When the phone tries to connect using TLS to the server I installed, it fails due to unknown CA. How do I configure it to send all 3 CA certificates? Is two the limit? The phone in question is a Polycom VVX 350 running UCD Software Version 6.4.7.4513.
Thanks for any help.
#Telephony
------------------------------
Andrew Klassen
------------------------------