Source note · SIP TLS handshake failures on trunks
Microsoft SIP endpoints currently accept SBC certificates that lack the Client Authentication EKU, and Microsoft expects this to continue for the foreseeable future with advance notice of any change.
Checked 2026-09-25
- Vendor
- Microsoft
- Product
- Teams Phone Direct Routing
- Subsystem
- SBC certificate
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- current as of 2026-09-25
- Checked
- 2026-09-25
Sources
- What's New Direct Routing — Microsoft · tier 2 current vendor documentation · Clarification on Client Authentication Extended Key Usage (EKU)
Cite this note
APA
WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-client-eku-not-required. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-client-eku-not-required
BibTeX
@misc{warmtransfer-claim-sip-tls-handshake-failures-dr-client-eku-not-required,
title = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-client-eku-not-required},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-client-eku-not-required},
note = {Source note sip-tls-handshake-failures-dr-client-eku-not-required, checked 2026-09-25}
}