TLS & Encryption

Status
Not open for further replies.

glennbtn

Member
Aug 7, 2018
72
3
8
53
Hi All

I am trying to get TLS and Encryption working. I have a company wide wildcard certificate install and tls enabled for the internal profile (we don't use the external as we lock it all down) There is a profile registered with 5061 so all good.

We use Zoiper, Snom and Yealink phones. I have enabled TLS and encryption on all and they all show in registrations as TLS. I can call from either the snom or yealink to Zoiper and active calls shows both as encrypted although if I look at the logs in the Snom I see

Dec 28 12:11:50.466 [ERROR ] TLS: BIO_new_bio_pair code 336151574, error:14094416:SSL routines:ssl3_read_bytes:sslv3 alert certificate unknown
Dec 28 12:11:50.466 [ERROR ] TLS: BIO_new_bio_pair code 336150757, error:140940E5:SSL routines:ssl3_read_bytes:ssl handshake failure
Dec 28 12:11:50.488 [WARN ] TLS: CertVerification for PhoneCtx disabled!

If I try and dial the snom or the Yealink the call just goes to voicemail. Clearly I am missing something here and it's not as simple as just enabling both TLS end Encryption on the devices.

The command line just shows
[INFO] mod_dptools.c:3637 Originate Failed. Cause: INCOMPATIBLE_DESTINATION

Any advise would be gratefully received

Thanks
 

Adrian Fretwell

Well-Known Member
Aug 13, 2017
1,498
413
83
Just a wild guess, but could the Snon be missing the root and/or intermediate certificate that signed your company wide wildcard certificate?
 
Status
Not open for further replies.