VoIP: SIP-over-TLS and sRTP: Belledonne Linphone

Last tested version

4.1
retested in May 2020 with 4.2.2

Configuration

SIP-URI User: Settings → SIP Accounts → Username
SIP-URI Host: Settings → SIP Accounts → Domain
… More options → Outbound proxy: Off
SIP-over-TLS: Settings → SIP Accounts → Transport: TLS
SDES-sRTP: Settings → Network → Media Encryption → SRTP
which is RTP/SAVP, 488, RTP/AVP

Software Bugs

SHA-2 Digest: does not pick MD5 if there is an unknown algorithm, continues without header Authorization; therefore not future proof

Security

Bugs: ECDHE curves with less than 224 bit
Privacy: app phones home to subscribe.linphone.org
in UNIX, the metadata of every call gets logged
Mitigation: in the file ~/.config/linphone/linphonerc, change quality_reporting_enabled

back to the other (soft) phones.