Source note · SIP TLS handshake failures on trunks
An SBC that began failing TLS toward Teams Direct Routing around the July 2026 CA rollout, with the failures showing as an unknown_ca or certificate-validation error on the SBC side, most plausibly lacks one of the seven listed roots in the trust store tied to the Teams TLS context.
inferred · Checked 2026-09-25
- Vendor
- Microsoft
- Product
- Teams Phone Direct Routing
- Subsystem
- trust store
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- end of July 2026 onward
- Status
- inferred
- Checked
- 2026-09-25
Sources
- What's New Direct Routing — Microsoft · tier 2 current vendor documentation · Testing endpoint (February 16, 2026) Warning box; Update on upcoming certificate changes (December 12, 2025) > Summary; read with RFC 8446 section 6.2 unknown_ca
Cite this note
APA
WarmTransfer. (2026, September 25). SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-unknown-ca-after-ms-ca. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-unknown-ca-after-ms-ca
BibTeX
@misc{warmtransfer-claim-sip-tls-handshake-failures-unknown-ca-after-ms-ca,
title = {SIP TLS handshake failures on trunks: source note sip-tls-handshake-failures-unknown-ca-after-ms-ca},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-tls-handshake-failures-unknown-ca-after-ms-ca},
note = {Source note sip-tls-handshake-failures-unknown-ca-after-ms-ca, checked 2026-09-25}
}