Saturday, October 10, 2026

Some notes on SIPS schema on Asterisk

I was a bit surprised to find out, that SIPS does not mean SIP-over-TLS, but can be seen on plain UDP. So, if you have something like 

SIPS endpoint - Kamailio (TLS/UDP) - Asterisk (UDP)

you will have SIPS schema leftovers in Asterisk, for example in the Contact field, which is totally fine and legit. But the issue is that, on 200 - ACK answer sequence (which is a source of a majority of problems in SIP), Asterisk (or, rather PJSIP) looks at the Contact header with SIPS schema and tries to use TLS. This starts with Asterisk versions that use PJSIP 2.17, so from 20.12 and above.

There could be 2 solutions:

  • Clean/restore SIPS schema on Kamailio.
  • Compile PJSIP with PJSIP_DONT_SWITCH_TO_TLS 1 flag.

The easiest way is to use while compiling

./configure ... PJPROJECT_CFLAGS='-DPJSIP_DONT_SWITCH_TO_TLS=1'

but it's only for Asterisk 22.11+ or edit the file third-party/pjproject/patches/config_site.h

No comments:

Post a Comment