Source note · SIP TLS handshake failures on trunks
Microsoft warns that some TLS libraries and SBCs may refuse outbound connections using a client certificate that lacks the Client Authentication EKU, even though the Teams SIP interface accepts such certificates.
Checked 2026-09-25
- Vendor
- Microsoft
- Product
- Teams Phone Direct Routing
- Subsystem
- mutual TLS
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- as stated in entry dated 2025-12-12
- Checked
- 2026-09-25
Sources
- What's New Direct Routing — Microsoft · tier 2 current vendor documentation · Update on upcoming certificate changes (December 12, 2025) > Summary, second bullet, last sentence
Cite this note
APA
WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-client-eku-lib-risk. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-client-eku-lib-risk
BibTeX
@misc{warmtransfer-claim-sip-tls-handshake-failures-dr-client-eku-lib-risk,
title = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-client-eku-lib-risk},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-client-eku-lib-risk},
note = {Source note sip-tls-handshake-failures-dr-client-eku-lib-risk, checked 2026-09-25}
}