Source note · SIP TLS handshake failures on trunks
A Direct Routing wildcard certificate covers only one label: *.contoso.com matches sbc1.contoso.com but not customer10.sbc1.contoso.com, and an FQDN that does not match the CN or SAN needs a new certificate.
Checked 2026-09-25
You can't have multiple levels of subdomains under a wildcard.
- Vendor
- Microsoft
- Product
- Teams Phone Direct Routing
- Subsystem
- SBC certificate
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- current as of 2026-09-25
- Checked
- 2026-09-25
Sources
- SBC connectivity issues — Microsoft · tier 2 current vendor documentation · SIP options issues > FQDN doesn't match the contents of CN or SAN in the provided certificate
Cite this note
APA
WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-wildcard-one-level. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-wildcard-one-level
BibTeX
@misc{warmtransfer-claim-sip-tls-handshake-failures-dr-wildcard-one-level,
title = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-dr-wildcard-one-level},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-dr-wildcard-one-level},
note = {Source note sip-tls-handshake-failures-dr-wildcard-one-level, checked 2026-09-25}
}