Source record · tier 2 current vendor documentation
TLS trunk transport protocol specification for BYOC Cloud
- Publisher
- Genesys
- URL
- https://help.genesys.cloud/articles/tls-trunk-transport-protocol-specification/
- Published
- unknown
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Genesys proprietary documentation; no-redistribution; short excerpts and locators only
Source notes citing this source
- For TLS, the customer endpoint needs a certificate from a public CA that Genesys trusts, with a common name or subject alternative name that matches a hostname in the trunk's SIP Servers or Proxies. IP addresses are not accepted for this match. in context
- BYOC Cloud TLS trunks support one-way (server-side) TLS only. Mutual TLS is not supported. in context
- A BYOC Cloud trunk that uses TLS signalling requires SRTP for call media. in context
- BYOC Cloud server certificates are signed by Amazon Trust Services on Dynamic Cloud Voice and by DigiCert on Legacy Cloud Voice. in context
- A BYOC Cloud TLS trunk supports only TLS 1.2, on port 5061. in context
- The customer endpoint certificate's common name or subject alternative name must match the value used as the trunk's SIP Servers or Proxies setting; the BYOC endpoint validates by host name, and an IP address is not acceptable. in context
- For BYOC Cloud TLS trunks, the customer endpoint certificate must be signed by one of the public certificate authorities Genesys lists; an unsigned (self-signed) certificate makes the connection fail. in context
- Secure BYOC Cloud connections fail if the active certificate has expired or is not yet valid, and an incorrectly set up customer endpoint certificate can cause outbound calls to fail. in context
- For BYOC Cloud TLS, the Legacy Cloud Voice platform supports only the secp384r1 ECDHE curve, while the Dynamic Cloud Voice Platform supports both secp256r1 and secp384r1. in context
- A BYOC Cloud TLS trunk whose SIP Servers or Proxies value is an IP address rather than a host name will fail certificate validation even if the certificate itself is valid. inferred in context
- BYOC Cloud does not support IPsec for secure trunks. in context
- BYOC Cloud does not support mutual TLS on trunks. in context
- BYOC Cloud secure trunks use TLS 1.2 on port 5061, with SIP over TLS (SIPS) for signalling and SRTP for media. in context
- On 2025-03-24 Genesys announced that a future release would drop the BYOC Cloud TLS ciphers TLS_RSA_WITH_AES_256_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384. in context
- BYOC Cloud does not support IPsec for secure trunks. in context
- BYOC Cloud TLS connections use one-way (server-side) TLS; mutual TLS is not supported. in context
- Certificates on a BYOC Cloud TLS trunk endpoint must be signed by a public certificate authority from the list Genesys publishes, and must contain the subject name of the URI the client connected to. in context
- Genesys Cloud BYOC endpoints on the Legacy Cloud Voice platform present DigiCert certificates, while the Dynamic Cloud Voice platform uses Amazon Trust Services roots (Amazon Root CA 1 and 2). in context
- For secure BYOC Cloud trunks, carriers must support SIP over TLS over TCP together with SRTP for media. in context
- BYOC Cloud supports TLS endpoints using TLS version 1.2, with TLS listeners on port 5061. in context
- BYOC Cloud TLS connections use one-way server-side TLS and mutual TLS is not supported. in context
- Remote endpoints receiving SIP TLS from BYOC Cloud must present an X.509 certificate signed by one of the public certificate authorities Genesys lists. in context
- BYOC Cloud supports TLS 1.2 endpoints and its TLS listeners are on port 5061. in context
- With a Local Gateway between the platforms, the SBC runs two independent TLS legs: one toward Webex Calling under Cisco's certificate rules and one toward Genesys BYOC Cloud where mutual TLS is not supported. inferred in context
Cite this source record
APA
WarmTransfer. (2026, September 24). TLS trunk transport protocol specification for BYOC Cloud. WarmTransfer. https://warmtransfer.net/knowledge/sources/genesys-help-tls-trunk-transport-spec
BibTeX
@misc{warmtransfer-genesys-help-tls-trunk-transport-spec,
title = {TLS trunk transport protocol specification for BYOC Cloud},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/genesys-help-tls-trunk-transport-spec},
note = {Genesys, accessed 2026-09-24}
}