Solved 3CX Phonebook cannot download remote phonebook error

Status
Not open for further replies.

johnpi

Customer
Advanced Certified
Joined
May 2, 2018
Messages
39
Reaction score
5
Yesterday and since the system was implemented, all of my Yealink phones, which are auto-provisioned through the 3CX server, always displayed the 3CX Phonebook properly. Today all of my Yealink 46S phones return an error of "Cannot download remote phonebook!". I take it this transition probably occurred last night since it's standard for all phones to be reprovisioned nightly. I can go to the url of the xml file and view it in a browser just fine. The url look the same in the phone UI under the directory tab, although it uses http but the actual link redirects to https, but with the same URL, and this hasn't changed. So what changed will be the question, and the only thing changed in the past day is I added the intermediate CA into the certificate chain for the 3cx server cert and restarted successfully nginx because Firefox was complaining about it missing, which it is right and my mistake for not initially adding it into the original pem file.

Anyway, I just wanted to put this out there as I start to troubleshoot, just to see if anyone else ran into a similar issue where the Yealink phones can't download the phonebook.
 
Hello @johnpi

If the phones are provisioned as local devices to the PBX then the phonebook URL should be http. If the phones are remote however then the phonebook URL should be https.
I would recommend making a change to a device like adding a blf key and try to reprovision. Is the change applied to the phone? This will tell you if the issue is just with the phonebook or with reprovisioning in general since you made a certificate change.
 
YiannisH, thanks for the response.
As long as you handle the redirect correctly from the webservice (3cx server) then you can use http for both local and remote. In my case the nginx redirect works perfect and is a very common practice. The issue actually turned out to be the Yealink phones. They have a very small set of 30 publicly trusted CAs stored on the phones, so if you use say an intermediate that isn't one of these 30, then you either need to add it in or set the "Only Accept Trusted Certificates" to disabled.
 
  • Like
Reactions: craigreilly
Glad to see the issue has been resolved and thank you for updating the thread with your solution.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet