" /> SIPServer TLS, without certificate - Genesys CTI User Forum

Author Topic: SIPServer TLS, without certificate  (Read 4019 times)

Offline alexandercoachman

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 0
SIPServer TLS, without certificate
« on: October 03, 2011, 03:59:02 PM »
Advertisement
I would like to connect my SIP Server to an external gateway. We have problems with the TCP connections (doesnt arrives a TCP ACK), so we would like to try with TLS.

I set this option in the SIPServer application to 5061, I restarted the SIPServer but the netstat doesnt shows the listening port. In the SIP server logs I found:

7:21:57.250:(1) TLS options not configured correctly for port=5061.

I know, that I should use a certificate, but it doesnt work without this?

Rgds, Sandor

Offline René

  • Administrator
  • Hero Member
  • *****
  • Posts: 1832
  • Karma: 62
Re: SIPServer TLS, without certificate
« Reply #1 on: October 03, 2011, 06:25:24 PM »
Hi,

Certificate is mandatory for TLS and it cannot work without it. Please read some info about TLS (SSL) to understand how it works.

R.

Offline alexandercoachman

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 0
Re: SIPServer TLS, without certificate
« Reply #2 on: October 03, 2011, 08:54:17 PM »
Thanks René.

Offline alexandercoachman

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 0
Re: SIPServer TLS, without certificate
« Reply #3 on: October 04, 2011, 11:15:13 AM »
Should I configure another genesys components with TLS, or is it enough on the trunk DN? Should I configure it on VoIP DN (treatment service)?

We have a working TLS connection between SIPServer and an external gateway, but when the media stream starts, (in logs it seems that everything works fine) on the client videoconferencing system doesnt appear any video or voice...

Any ideas?
« Last Edit: October 04, 2011, 11:16:59 AM by alexandercoachman »

Offline alexandercoachman

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 0
Re: SIPServer TLS, without certificate
« Reply #4 on: October 04, 2011, 11:15:55 AM »
And this is the same problem with using TCP.
??? ??? ??? ??? ??? ??? ??? ??? ???

I dont have any idea how to resolve this...

Offline rpenney

  • Jr. Member
  • **
  • Posts: 64
  • Karma: 2
Re: SIPServer TLS, without certificate
« Reply #5 on: October 06, 2011, 12:54:00 PM »
Wireshark is your friend  :D

See where you can span the traffic and use the features of Wireshark to look at the SIP messages and the RTP streams.

You can often get the gateway to span the traffic for you.

Add the TLS certificates into wireshark and it will decode the streams.

What are you using to generate the video or voice?


Offline Allan

  • Newbie
  • *
  • Posts: 39
  • Karma: -1
Re: SIPServer TLS, without certificate
« Reply #6 on: October 12, 2011, 01:55:11 PM »
Refer page 87 of the Security Deployment guide onwards

Offline alexandercoachman

  • Jr. Member
  • **
  • Posts: 61
  • Karma: 0
Re: SIPServer TLS, without certificate
« Reply #7 on: October 12, 2011, 03:10:00 PM »
Thank you Allan.
It works now with thumbprint.

Sandor