TLS defines distinct certificate alerts: bad_certificate (42), unsupported_certificate (43), certificate_revoked (44), certificate_expired (45, also sent for not-yet-valid certificates), certificate_unknown (46) and unknown_ca (48, for a chain that cannot be anchored in a trusted CA).

Checked 2026-09-25

Vendor
IETF
Product
TLS
Subsystem
TLS alerts
Deployment
any
Region
not restricted
Release range
TLS 1.3 (RFC 8446)
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-rfc8446-cert-alerts. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-rfc8446-cert-alerts

BibTeX

@misc{warmtransfer-claim-sip-tls-handshake-failures-rfc8446-cert-alerts,
  title  = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-rfc8446-cert-alerts},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-rfc8446-cert-alerts},
  note   = {Source note sip-tls-handshake-failures-rfc8446-cert-alerts, checked 2026-09-25}
}

Read in context