SIP TLS Certificate Validation Failing on AP-Southeast-1 BYOC Trunks

Can anyone clarify why SIP TLS registration is failing with 401 Unauthorized on our AP-Southeast-1 BYOC trunks after the recent certificate rotation? The intermediate CA is valid and trusted, yet the carrier gateway rejects the handshake.

  1. Updated SIP credentials in Genesys Cloud trunk configuration.
  2. Verified TLS 1.2 is enabled on the carrier side.
  3. Observed SIP/2.0 401 Unauthorized in the signaling logs immediately after registration attempt.