RFC 5922 takes a SIP domain identity from the certificate's subjectAltName, either a URI of scheme sip with no userinfo or a DNS name, and permits examining the CN only if no subjectAltName is present.

Checked 2026-09-25

If and only if the subjectAltName does not appear in the certificate, the implementation MAY examine the CN field of the certificate.
Vendor
IETF
Product
SIP
Subsystem
server identity validation
Deployment
any
Region
not restricted
Release range
RFC 5922 (June 2010)
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-rfc5922-san-precedence. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-rfc5922-san-precedence

BibTeX

@misc{warmtransfer-claim-sip-tls-handshake-failures-rfc5922-san-precedence,
  title  = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-rfc5922-san-precedence},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-rfc5922-san-precedence},
  note   = {Source note sip-tls-handshake-failures-rfc5922-san-precedence, checked 2026-09-25}
}

Read in context