Source note · SIP TLS handshake failures on trunks
On a registration-based Local Gateway, 'crypto signaling default trustpoint EmptyTP cn-san-validate server' under sip-ua makes the gateway permit the connection only if the host name configured in tenant 200 appears in the peer certificate's CN or SAN.
Checked 2026-09-25
- Vendor
- Cisco
- Product
- Webex Calling Local Gateway (IOS XE)
- Subsystem
- server identity validation
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- current as of 2026-09-25
- Checked
- 2026-09-25
Sources
- Configure Local Gateway on Cisco IOS XE for Webex Calling — Cisco Systems, Inc. (Webex Help Center) · tier 2 current vendor documentation · Registration-based trunk configuration, sip-ua block explanation
Cite this note
APA
WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-lgw-cn-san-validate. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-lgw-cn-san-validate
BibTeX
@misc{warmtransfer-claim-sip-tls-handshake-failures-lgw-cn-san-validate,
title = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-lgw-cn-san-validate},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-lgw-cn-san-validate},
note = {Source note sip-tls-handshake-failures-lgw-cn-san-validate, checked 2026-09-25}
}