<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article How do I use encryption with Elastic SIP Trunking? in Elastic SIP Trunking</title>
    <link>https://community.sinch.com/t5/Elastic-SIP-Trunking/How-do-I-use-encryption-with-Elastic-SIP-Trunking/ta-p/16691</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;All Sinch Elastic SIP Trunks support TLS and SRTP natively. For more information on TLS/SRTP encryption and the benefits of using it, please read more &lt;A href="https://sinch.com/glossary/tlssrtp/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make encrypted calls with TLS simply send calls to your SIP Trunk FQDN on port 5061.&amp;nbsp; &amp;nbsp;This port can only be used for TLS, and non-TLS calls will fail. &amp;nbsp;SRTP must be used when making a TLS call.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To ensure we send calls to your infrastructure using TLS go into your SIP Endpoint on your SIP Trunk and change the transport protocol to “TLS”.&amp;nbsp; Note, that the port on your SIP endpoint will update automatically to port 5061.&amp;nbsp; In the event your infrastructure is listening for TLS connections on a non-standard port simply change the port manually to the correct value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="est tls.png" style="width: 999px;"&gt;&lt;img src="https://community.sinch.com/t5/image/serverpage/image-id/5541i6D1A40DD6596D884/image-size/large?v=v2&amp;amp;px=999" role="button" title="est tls.png" alt="est tls.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Congratulations, your Sinch Elastic SIP Trunk is now configured to use encryption!&amp;nbsp; It’s that easy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Let's Encrypt Certificates&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinch Elastic SIP Trunking uses TLS certificates secured by Let’s Encrypt.&amp;nbsp; If your TLS SIP Infrastructure does not already trust certificates from this Certificate Authority you can download the Let’s Encrypt Root Certificate and associate Intermediate certificates here: &lt;A href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fletsencrypt.org%2Fcertificates%2F&amp;amp;data=05%7C02%7CAlex.Sberna%40sinch.com%7Cc42dd4b7ec6240fb8a5808dcf82e39cf%7C3b518aae89214a7b8497619d756ce20e%7C0%7C0%7C638658124711395957%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=hk%2F5YSKSpDw6fe7sIUsCsESl6kIkpZVVuRPS8v4gg0Y%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://letsencrypt.org/certificates/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Cypher Suite Support&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinch trusts all well-known Certificate Authorities. &amp;nbsp;This ensures we will not have any trust issues when your infrastructure presents its certificate on inbound calls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For negotiation Sinch supports the following Cypher Suites for both TLS and SRTP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;TLSv1.2&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CCM&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CCM&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;TLSv1.3&lt;/STRONG&gt; &lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS_AES_256_GCM_SHA384&lt;/P&gt;
&lt;P&gt;TLS_CHACHA20_POLY1305_SHA256&lt;/P&gt;
&lt;P&gt;TLS_AES_128_GCM_SHA256&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 29 Oct 2024 17:52:48 GMT</pubDate>
    <dc:creator>Alex_Sberna</dc:creator>
    <dc:date>2024-10-29T17:52:48Z</dc:date>
    <item>
      <title>How do I use encryption with Elastic SIP Trunking?</title>
      <link>https://community.sinch.com/t5/Elastic-SIP-Trunking/How-do-I-use-encryption-with-Elastic-SIP-Trunking/ta-p/16691</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;All Sinch Elastic SIP Trunks support TLS and SRTP natively. For more information on TLS/SRTP encryption and the benefits of using it, please read more &lt;A href="https://sinch.com/glossary/tlssrtp/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make encrypted calls with TLS simply send calls to your SIP Trunk FQDN on port 5061.&amp;nbsp; &amp;nbsp;This port can only be used for TLS, and non-TLS calls will fail. &amp;nbsp;SRTP must be used when making a TLS call.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To ensure we send calls to your infrastructure using TLS go into your SIP Endpoint on your SIP Trunk and change the transport protocol to “TLS”.&amp;nbsp; Note, that the port on your SIP endpoint will update automatically to port 5061.&amp;nbsp; In the event your infrastructure is listening for TLS connections on a non-standard port simply change the port manually to the correct value.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="est tls.png" style="width: 999px;"&gt;&lt;img src="https://community.sinch.com/t5/image/serverpage/image-id/5541i6D1A40DD6596D884/image-size/large?v=v2&amp;amp;px=999" role="button" title="est tls.png" alt="est tls.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Congratulations, your Sinch Elastic SIP Trunk is now configured to use encryption!&amp;nbsp; It’s that easy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Let's Encrypt Certificates&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinch Elastic SIP Trunking uses TLS certificates secured by Let’s Encrypt.&amp;nbsp; If your TLS SIP Infrastructure does not already trust certificates from this Certificate Authority you can download the Let’s Encrypt Root Certificate and associate Intermediate certificates here: &lt;A href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fletsencrypt.org%2Fcertificates%2F&amp;amp;data=05%7C02%7CAlex.Sberna%40sinch.com%7Cc42dd4b7ec6240fb8a5808dcf82e39cf%7C3b518aae89214a7b8497619d756ce20e%7C0%7C0%7C638658124711395957%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=hk%2F5YSKSpDw6fe7sIUsCsESl6kIkpZVVuRPS8v4gg0Y%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://letsencrypt.org/certificates/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Cypher Suite Support&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinch trusts all well-known Certificate Authorities. &amp;nbsp;This ensures we will not have any trust issues when your infrastructure presents its certificate on inbound calls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For negotiation Sinch supports the following Cypher Suites for both TLS and SRTP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;TLSv1.2&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CCM&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CCM&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256&lt;/P&gt;
&lt;P&gt;TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;TLSv1.3&lt;/STRONG&gt; &lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TLS_AES_256_GCM_SHA384&lt;/P&gt;
&lt;P&gt;TLS_CHACHA20_POLY1305_SHA256&lt;/P&gt;
&lt;P&gt;TLS_AES_128_GCM_SHA256&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Oct 2024 17:52:48 GMT</pubDate>
      <guid>https://community.sinch.com/t5/Elastic-SIP-Trunking/How-do-I-use-encryption-with-Elastic-SIP-Trunking/ta-p/16691</guid>
      <dc:creator>Alex_Sberna</dc:creator>
      <dc:date>2024-10-29T17:52:48Z</dc:date>
    </item>
  </channel>
</rss>

