I think the issue here is the ca_list setting. As far as I know this needs to be created including both the LE CA certs but also the specific MS CA certs.

- Barry Flanagan




On 15 Aug 2024, at 15:59, Henning Westerholt via sr-users <sr-users@lists.kamailio.org> wrote:

Hello Fred,

letsencrypt works just fine with MS Teams.

Cheers,

Henning

-----Original Message-----
From: Fred Posner via sr-users <sr-users@lists.kamailio.org>
Sent: Donnerstag, 15. August 2024 16:30
To: Kamailio (SER) - Users Mailing List <sr-users@lists.kamailio.org>
Cc: Fred Posner <fred@qxork.com>
Subject: [SR-Users] Re: certificate verify failed (sni: unknown) integration with
ms teams


On Aug 15, 2024, at 8:46 AM, Muhammad Sohaib via sr-users <sr-
users@lists.kamailio.org> wrote:

Dear all,

[snip]
tls.cfg:

[server:default]
method = TLSv1.2+
verify_certificate = yes
require_certificate = yes
private_key = /etc/letsencrypt/live/test.mytest.com/privkey.pem
certificate = /etc/letsencrypt/live/test.mytest.com/fullchain.pem
ca_list = /etc/letsencrypt/live/test.mytest.com/fullchain.pem
server_name = test.mytest.com

[client:default]
method = TLSv1.2+
verify_certificate = yes
require_certificate = yes
private_key = /etc/letsencrypt/live/test.mytest.com/privkey.pem
certificate = /etc/letsencrypt/live/test.mytest.com/fullchain.pem
ca_list = /etc/letsencrypt/live/test.mytest.com/fullchain.pem

Please suggest what I am missing.


There should be a document from MS about the certificates they are willing to
accept. I’m fairly certain they do not accept letsencrypt.


Regards,

Fred Posner
https://www.fredoso.com




__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions To unsubscribe
send an email to sr-users-leave@lists.kamailio.org
Important: keep the mailing list in the recipients, do not reply only to the
sender!
Edit mailing list options or unsubscribe:
__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions
To unsubscribe send an email to sr-users-leave@lists.kamailio.org
Important: keep the mailing list in the recipients, do not reply only to the sender!
Edit mailing list options or unsubscribe: