Log In
Developer Network
Technologies
Join the Network
Member Services
Events & Community
Unified Communications Manager SIP (SIP) Developer Center
Overview
Documentation
Community
Wiki
Testing
Everything
This Site
Blogs
9.1 SIP Documentation Now Available
Adrienne Moherek
10 Jan 2013
Unified Communications 9.0 Partner Bundle Offer Now Available to Order
Amanda Whaley
21 Sep 2012
Update - Silent Monitoring/Recording Supported Devices
George Gary
31 Aug 2012
Developer Partner 2012 US Update Presentations Available
George Gary
29 Jun 2012
Developer Partner 2012 London Update Presentations Available
George Gary
10 Feb 2012
Showing 1 - 5 of 21 results.
Items per Page 5
Page
(Changing the value of this field will reload the page.)
1
2
3
4
5
of 5
First
Previous
Next
Last
Forums
Message Boards Home
Recent Posts
Statistics
Answer
(
Unmark
)
Mark as an Answer
« Back to SIP Trunk Questions
Unexpected X.509 subject name for TLS SIP Trunk
Threads [
Previous
|
Next
]
Graham Schofield
Posts:
2
Join Date:
10/27/10
Recent Posts
Unexpected X.509 subject name for TLS SIP Trunk
sip
security
tls
x.509
Answer
8/17/12 3:55 PM
Mark as an Answer
Submit
Reply with Quote
Quick Reply
Hello,
I am trying to configure a TLS connection to a SIP trunk for secure recording. I have generated a test certificate and uploaded it to the CUCM and added its subject name to a SIP Trunk Security Profile and assigned that profile to the SIP Trunk I am using setting the SRTP Allowed and "Whenusing both sRTP and TLS" for the secure traffic option. When I try to record a call the CUCM sends me an INVITE over a TLS connection (looking at Wireshark) but then after the 200OK etc. it sends a BYE straight away.
Lpooking at the logs using RTMT I can see:
SIPHandler(1,100,71,1) |SIPTcp(1,100,63,1) |1,100,17,70.3^*^* |[T:N-H:0,N:0,L:0,V:0,Z:0,D:0] connIdx= 74 --remoteIP=192.0.0.57 --remotePort = 5061 --X509SubjectName /CN=My Recording/ST=Someplace/C=UK/O=My Recorders Ltd --Cipher AES128-SHA --SubjectAltname =
then:
TLS InvalidX509NameInCertificate Error (reason 2), Rcvd=Red, Expected=O=My Recorders Ltd,C=UK,ST=Someplace,CN=My Recording
then the CUCM rejects the call as the TLS connection is unsecure.
The subject name is the same as the subject name in the CUCM Security->Certificates list
When I extract the subject name from the certificate in OpenSSL I get:
Subject: CN=My Recording, ST=Someplace, C=UK, O=My Recorders Ltd
I don't understand why the certificate name is being displayed differently at different places in the logs. Why does the CUCM not like the subject name of the certificate when all parties are using the same self-signed test certificate?
Sign in to vote.
Flag
Please sign in to flag this as inappropriate.
Top
Collateral
No files available