Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Avaya SBC Not sending certificates to peer.

Status
Not open for further replies.

walruses

Technical User
Apr 1, 2016
68
0
6
MX
Hi, does anyone have an opinion about this issue?

I have installed certificates in my SBC so I can connect to Genesys. In a TLS trace I can see that I am receiving Genesys certificates but I am not sending mine. I have checked interfaces, profiles, network flows and I can not see where the problem is.

Any Idea?

Best regards.
 
Can you provide an example from a tracesbc? What is the exact error? What is the SBC release?
 
Hi Arlo555, in a trace my provider sais that I should be sending a key as in the example attached (key). Plus he sais I am not sending my CA cert I got an error as in the image attached (cert)
cert_vvgypk.png
key_hpc56d.png
 
Check that you’ve uploaded the correct root CA / bundle to EMS

I had similar problems with some comodo certs as they had so many root CAs finding the right one was a mare
 
Walruses,

I agree with biglebowski, Try this display filter(tls.handshake.type == 11) You should be able to see the certificate being offered by Genesis. If you click into the Transport Layer Security in the packet details pane you can verify the root CA you need to load on your SBC and set in the TLS profile. You can read it faster in a tracesbc though. Best of Luck.

Screenshot_2023-11-19_at_5.12.01_PM_m21f3k.png

 
 https://files.engineering.com/getfile.aspx?folder=8addadd5-d345-46ca-aeb2-8f459d342c3c&file=Screenshot_2023-11-19_at_5.12.01?PM.png
Thank you very much biglebowski, Arlo555, certificates were right from Genesys and Avaya but it was necessary to apply a TLS Client and Server Profile in Sip Server and Network Flow so Avaya certificate could be added in the tls handshake.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top