The default certificates are self-signed. A client may not recognize these as trustworthy, policy may claim that only certificates signed by a well-known CA that the client has root certificates for is trusted, so the TLS connection will not be completed.
If the client sets up a TLS connection anyway, that's fine. There will be encryption, but no authentication. The client should not show any lock in this case or in any way indicate a "secure" connection to the server. The connection should not be trusted for exchange of media encryption keys or any other confidential data.
/O
--
* Olle E. Johansson -
oej@edvina.net* Kamailio & SIP Masterclass Miami FL, Oxford UK and Malaga, Spain this spring!