<div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif">Bodgan, </div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">Thanks . Yes that one wasn’t an error but i had the wrong private key configured and the socket was disconnecting so i was able to generate new certs and it worked fine. I got some help from IRC. </div><div class="gmail_default" style="font-family:tahoma,sans-serif">I still see the notice but the socket stays up and i can register. </div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">Right now i have the signaling working perfect, but i have no audio either way. Im trying to figure out why rtpengine is not working correctly. </div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">Thanks again </div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jan 19, 2016 at 5:21 AM, Bogdan-Andrei Iancu <span dir="ltr">&lt;<a href="mailto:bogdan@opensips.org" target="_blank">bogdan@opensips.org</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  
    
  
  <div bgcolor="#FFFFFF" text="#000000">
    Hi Sebastian,<br>
    <br>
    That message is just an INFO (not an error) - you say TLS handshake
    fails on opensips side as it expects a certificate from the end
    point ?<br>
    <br>
    Regards,<br>
    <pre cols="72">Bogdan-Andrei Iancu
OpenSIPS Founder and Developer
<a href="http://www.opensips-solutions.com" target="_blank">http://www.opensips-solutions.com</a></pre><div><div class="h5">
    <div>On 18.01.2016 06:32, Sebastian Sastre
      wrote:<br>
    </div>
    </div></div><blockquote type="cite"><div><div class="h5">
      <div dir="ltr">
        <div class="gmail_default">
          <div class="gmail_default"><font face="tahoma, sans-serif">I’ve
              been trying to setup WSS using 2.2 latest branch. </font></div>
          <div class="gmail_default"><br>
          </div>
          <div class="gmail_default"><font face="tahoma, sans-serif">When
              trying to open the web socket i get “ Client did not
              present a TLS certificate” . Im using the included default
              ssl certs for the server to avoid mistakes . What
              certificate is the user supposed to present? </font></div>
          <div class="gmail_default"><font face="tahoma, sans-serif"><br>
            </font></div>
          <div class="gmail_default"><font face="tahoma, sans-serif">I
              tried using sip.js and jssip to connect without any luck.
              i also tried disabling cert requirement but didn’t work. </font></div>
          <div style="font-family:tahoma,sans-serif"><br>
          </div>
          <div style="font-family:tahoma,sans-serif">—— Config ——-</div>
          <div style="font-family:tahoma,sans-serif"><br>
          </div>
          <div style="font-family:tahoma,sans-serif"><span style="font-family:arial,sans-serif;font-size:13px">listen=</span><a style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:13px"></a><a>wss:123.456.789.987:5060</a><br style="font-family:arial,sans-serif;font-size:13px">
            <span style="font-family:arial,sans-serif;font-size:13px">listen=tls:123.456.789.987:</span><span style="font-family:arial,sans-serif;font-size:13px">5061</span><br>
          </div>
          <div style="font-family:tahoma,sans-serif"><span style="font-family:arial,sans-serif;font-size:13px">listen=</span><a style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:13px"></a><a>wss:123.456.789.987:443</a><br>
          </div>
          <div style="font-family:tahoma,sans-serif"><span style="font-family:arial,sans-serif;font-size:13px"><br>
            </span></div>
          <div>
            <div><font face="tahoma, sans-serif">load
                module &quot;proto_udp.so&quot;</font></div>
            <div><font face="tahoma, sans-serif">load
                module “proto_tls.so”</font></div>
            <div><font face="tahoma, sans-serif">loadmodule
                &quot;proto_wss.so&quot;</font></div>
          </div>
          <div style="font-family:tahoma,sans-serif"><br>
          </div>
          <div>
            <div><font face="tahoma, sans-serif">loadmodule &quot;tls_mgm.so&quot;</font></div>
            <div><font face="tahoma, sans-serif">modparam(&quot;tls_mgm&quot;,
                &quot;certificate&quot;, &quot;/etc/opensips/tls/rootCA/cacert.pem&quot;)  
                        </font></div>
            <div><font face="tahoma, sans-serif">modparam(&quot;tls_mgm&quot;,
                &quot;private_key&quot;,
                &quot;/etc/opensips/tls/rootCA/private/cakey.pem&quot;)    </font></div>
            <div><font face="tahoma, sans-serif">modparam(&quot;tls_mgm&quot;,
                &quot;ca_list&quot;, &quot;/etc/opensips/tls/rootCA/cacert.pem&quot;)      
                         </font></div>
            <div><font face="tahoma, sans-serif">modparam(&quot;tls_mgm&quot;,
                &quot;ca_dir&quot;, &quot;/etc/opensips/tls/rootCA/&quot;)  </font></div>
            <div><font face="tahoma, sans-serif">modparam(&quot;tls_mgm&quot;,
                &quot;require_cert&quot;, &quot;0&quot;) </font></div>
            <div><font face="tahoma, sans-serif">modparam(“tls_mgm&quot;,
                &quot;verify_cert&quot;, &quot;0&quot;)</font></div>
          </div>
          <div><font face="tahoma, sans-serif"><br>
            </font></div>
          <div><font face="tahoma, sans-serif"><br>
            </font></div>
          <div><font face="tahoma, sans-serif">——- Logs ——-</font><br>
          </div>
          <div>
            <div class="gmail_default"><span style="font-family:tahoma,sans-serif">/sbin/opensips[12468]:
                <a>INFO:core:probe_max_sock_buff</a>: using snd buffer of 416
                kb</span><br>
            </div>
            <div class="gmail_default"><font face="tahoma, sans-serif">/sbin/opensips[12468]:
                <a>INFO:core:init_sock_keepalive</a>: TCP keepalive enabled on
                socket 37</font></div>
            <div class="gmail_default"><font face="tahoma, sans-serif">/sbin/opensips[12460]:
                <a>INFO:proto_wss:ls_accept</a>: New TLS connection from
                xx.xx.xx.xx:50815 accepted</font></div>
            <div class="gmail_default"><font face="tahoma, sans-serif">/sbin/opensips[12460]:
                <a>INFO:proto_wss:tls_accept</a>: Client did not present a TLS
                certificate</font></div>
            <div class="gmail_default"><font face="tahoma, sans-serif">/sbin/opensips[12460]:
                <a>INFO:proto_wss:ls_dump_cert_info</a>: tls_accept: local TLS
                server certificate subject: /CN=OpenSIPS/ST=<a href="http://opensips.org/C=IP/emailAddress=team@opensips.org/O=opensips.org" target="_blank"></a><a href="mailto:opensips.org/C=IP/emailAddress=team@opensips.org/O=opensips.org" target="_blank">opensips.org/C=IP/emailAddress=team@opensips.org/O=opensips.org</a>,
                issuer: /CN=OpenSIPS/ST=<a href="http://opensips.org/C=IP/emailAddress=team@opensips.org/O=opensips.org" target="_blank">opensips.org/C=IP/emailAddress=team@opensips.org/O=opensips.org</a></font></div>
          </div>
          <div class="gmail_default"><font face="tahoma, sans-serif"><br>
            </font></div>
          <div class="gmail_default"><font face="tahoma, sans-serif"><br>
            </font></div>
          <div style="font-family:tahoma,sans-serif">Thanks ! </div>
          <div style="font-family:tahoma,sans-serif"><br>
          </div>
        </div>
      </div>
      <br>
      <fieldset></fieldset>
      <br>
      </div></div><pre>_______________________________________________
Users mailing list
<a href="mailto:Users@lists.opensips.org" target="_blank">Users@lists.opensips.org</a>
<a href="http://lists.opensips.org/cgi-bin/mailman/listinfo/users" target="_blank">http://lists.opensips.org/cgi-bin/mailman/listinfo/users</a>
</pre>
    </blockquote>
    <br>
  </div>

</blockquote></div><br></div>