Because TLS 1.3 encrypts the Certificate messages, a plain packet capture of a TLS 1.3 SIP trunk cannot show whether the SBC sent its intermediates; Microsoft's capture-based check for a missing chain works directly only on TLS 1.2 sessions, and TLS 1.3 needs a key log or device-side debugs.

inferred · Checked 2026-09-25

Vendor
multi-vendor
Product
SIP trunks over TLS
Subsystem
packet capture analysis
Deployment
any
Region
not restricted
Release range
TLS 1.3 sessions
Status
inferred
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-capture-tls13-blind. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-capture-tls13-blind

BibTeX

@misc{warmtransfer-claim-sip-tls-handshake-failures-capture-tls13-blind,
  title  = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-capture-tls13-blind},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-capture-tls13-blind},
  note   = {Source note sip-tls-handshake-failures-capture-tls13-blind, checked 2026-09-25}
}

Read in context