certificate

  1. Solved Let's Encrypt cert renewal : issuer not in server's trust store

    Hello all, This night, one of my debian 3CX server renewed its Let's Encrypt certificate automatically, as usual. But it came with a new issuer this time. previously : CN=R13,O=Let's Encrypt,C=US since today : CN=YR1,O=Let's Encrypt,C=US It appears that the new CA/chain is not present in the...
  2. Move to linux and change hostname?

    Currently with small Windows systems the hostname and hence the certificate are shared by the Windows instance and by 3CX - lets say server.company.com . If we break them out to Linux (either as physical box or VM) the hostname must change. I know previously that hostname and license were tied...
  3. Disable certificate auto-renewal

    Hi! I'm using on promise Pro version of 3CX with custom certificate installed. After latest updates certificate automatically renews every day to the Let's encrypt cert used by 3CX FQDN. Is it possible to disable that scheduled task? Thank you.
  4. Nginx SSL config changing after update

    Hello everyone, We're running multiple own-hosted/on-prem 3CX servers. Recently I changed all of them to use letsencrypt certificates and set it up as per the instructions in this thread which worked excellently. Over the weekend 3CX auto update kicked in and upgraded all of them to the 18.0...
  5. New Install via 3CX Deployment - HSTS Error on Admin Page

    Aloha, I've run the 3CX deployment wizard to DigitalOcean and to AWS a few times before with no issue, however, this time I've run into a snag. The server came up correclty, calls are routing properly, however when accessing the HTTPS admin page I'm receiving an error in Firefox and Chrome...
  6. Certificate Issue

    Our certificate expired at the weekend and I'm trying to install the new one. The new certificate doesn't appear to be there. I will attach an image of where I saved the files and I have restarted the relevant service.
  7. kinetix

    Signed / Trusted Updates for 3CX Upgrades

    With all the new Security being implemented throughout networks, would be great if 3CX would sign their updates with certificates which would allow executables and update downloads to run trusted by various security applications. Mike.
  8. Solved Cert not renewing

    I'm running version 18 with a private FQDN. My cert has expired and I can't seem to get it to renew. I've tried /usr/lib/3cxpbx/PbxConfigTool -renew-certificates which completes without error but doesn't help. I've rebooted and restarted the web service. The certs in...
  9. NicholasBarnes

    System won't renew LE certificate

    Debian, self-hosted. I have an interesting problem from a customer who said "Oh yes, we're happy to manage our own system"... Turns out they hadn't updated it at all since it was installed early last year. Their LE certificate stopped renewing some time after May 6th this year. For the first...
  10. Pi SBC Licensing error

    Hi People I am trying to setup a Raspberry Pi 4 as a SBC. I have reloaded the Raspbian OS multiple times and ruled the OS of the Pi out as a potential problem. When I run the "wget https://downloads-global.3cx.com/downloads/misc/d10pi.zip; sudo bash d10pi.zip" command on the Pi the correct...
  11. Email certificate error on Passive server only

    We're in an active/passive setup and recently upgraded from 16.0.5 to 16.0.6. Emails no longer send from our passive server with the following error: I couldn't find any further information in a log file, but I may just not know where to look. Email works just fine on our Active server, so I...
  12. twindscheif

    Solved 3CX V16 - TLS SIP Trunk - No Wildcard-Support?!

    Hi there, i'm trying to change my current SIP-Trunk to use TLS + SRTP. Currently after change the registration fails immediately. My SIP-Provider told me that he cannot see my registration request. The Event-Log of 3CX states: 503 Certificate Validation Failure. I already retrieved the...
  13. How to regenerate SIP/TLS certificate for 3cx domain?

    Hi all, I lost my certificates that were generated at install time in the Secure SIP tab (#/app/settings/security/159/secure_sip). How can I regenerate them? It's a 3CX Provided FQDN and NOT a custom domain. Is there a way to force trigger a new generation somehow? Thanks
  14. Solved 3CX does not start after installation with intermediate-certificate

    Hello, We have the following Problem and hope to get help from this nice community as soon as possible. Our certificate expired a few days ago as we simply forgot to renew it. With a bit of worktime this is easy to fix. BUT! Here comes our problem: As we had some problems with snom-phones we...
  15. 3CX IOS TLS "Service Unavailable"

    Client ------------------------------------------------------- Phone: iPhone X iOS Version: 12.4.1 Jailbreak: NO Connection: WiFi / LTE 3CX iOS App Build: 16.0.1.606 Server ------------------------------------------------------- Server: On premise accessed over internet 3CX Server Build...
  16. FQDN and Certificate Renewal Failure

    Hi, Hope someone could help us with this issue. One of our clients who have 3cx installed in their server recently got new people hosting their domain. After the change over, we started getting the following error messages: HTTPS Certificate renewal Failed - The DNS zone that contains your...
  17. New guy to Debian & 3CX Help for SSL install

    Ok guys, My client has decided to roll out with a Debian 3CX that is a on-prem solution, in a virtualized server instance. So what I'm needing some help with is getting the SSL on the local Debian running. I know how to use the OPENSSL to create the .key & .csr files No problem there. However...
  18. Mizzi

    Solved 3CX Certificate Expired no solution found in forums

    Hi, I have been running tests on 3CX for the past 3 months but I shut down the Virtual Box for like 2 months and I guess it couldn't automatically renew the certificate which expired 15 days ago. Now I can not login to my console but android phones seem like they are online. I tried to put...
  19. techsitters

    Implemented Update Let's Encrypt Certificate Renewal Time

    Currently, the 3CX provided Let's Encrypt Certificate renews between 00:00 - 07:00. I am asking that 3CX change this to 00:00 - 05:00. In the US, it is not uncommon for west coast businesses to open at 05:00 to accommodate east coast clients (+3 hours) The long term goal would be to specify...
  20. Walter Santos

    Basic Certification Error Test

    Hello, I tried twice mad tests for basic certification, but every time I tried, I got an error and need to wait 30 days. Then I tried again I was not able to get a new one. Did someone has the same problem?