Solved 3CX SSL Domain Certificate not auto renewing

Status
Not open for further replies.

rr_john

Customer
Joined
Feb 6, 2022
Messages
2
Reaction score
0
Hi Team,

I'm having some issues with an SSL Certificate auto renewing on a 3CX hosted domain name. I've tried the usual with rebooting the server and forcing a manual SSL Update using the renew command

/usr/lib/3cxpbx/PbxConfigTool -renew-certificates

When checking the logs i get the following error indicating the renewal is failing

2022/02/06 04:24:04 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1/*****.co.3cx.us-crt.pem"
2022/02/06 04:29:43 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"
2022/02/06 04:34:57 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"
2022/02/06 04:39:58 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"
2022/02/06 04:45:22 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"
2022/02/06 04:50:34 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"
2022/02/06 04:55:43 [error] 563#563: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: r3.o.lencr.org, peer: 96.16.55.78:80, certificate: "/var/lib/3cxpbx/Bin/nginx/conf/Instance1//*****.co.3cx.us-crt.pem"


Does anyone have a solution to this? Its been down for over a week now and i can only access the portal using chrome and bypassing the certificate.


Thanks in advance
John K
 
What version of 3CX and where is 3CX installed?
 
Hi Cobaltit,

Latest version V18 with all updates installed, installed on AWS instance, self managed with 3CX FQDN.

John
 
@rr_john

Simply running the command is not enough, can you confirm if the SSL certificate has already expired or is close to expiring? Also, if it has expired and not renewed automatically yet, is this not the first time this happened for this instance?
 
Last edited by a moderator:
Brilliant!

Do feel free to start a new thread should you need anything else!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet