Interesting and helpful implementation guideline in RFC 6216:
"If a client is trying to set up a TLS connection to good.example.com and it gets a TLS connection set up with a server that presents a valid certificate but with the name evil.example.com, it will typically generate an error or warning of some type. "
No, if the client is a SIP proxy configured as an outbound proxy. What are the exact SIP return codes and Warnings we should send?
/O