3cx supplied let's encrypt certificate renewal failure

Status
Not open for further replies.

Redcomm

Customer
Joined
Jul 21, 2021
Messages
3
Reaction score
1
Not sure exactly where to post this question or search for a solution. Our certificate cannot renew due to a path error renewing
a 3cx supplied certificate.


The SSL Certificate renewal for ourdomain.ca.3cx.us failed - Error:
System.UnauthorizedAccessException: Access to the path '/var/lib/3cxpbx/Bin/nginx/conf/Instance1/dhparam.pem' is denied.
---> System.IO.IOException: Permission denied
--- End of inner exception stack trace ---
at Interop.ThrowExceptionForIoErrno(ErrorInfo errorInfo, String path, Boolean isDirectory, Func`2 errorRewriter)
at Microsoft.Win32.SafeHandles.SafeFileHandle.Open(String path, OpenFlags flags, Int32 mode)
at System.IO.FileStream.OpenHandle(FileMode mode, FileShare share, FileOptions options)
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share)
at System.IO.File.InternalWriteAllBytes(String path, Byte[] bytes)
at System.IO.File.WriteAllBytes(String path, Byte[] bytes)
at PostInstall.CertificateGenerator.SaveFile(String fullPath, Byte[] content, String comment)
at PostInstall.CertificateGenerator.ProcessCertificatesDirectory(String directory, Boolean temporaryCertificateGenerated, Int32 regenerateNotSelfSignedCertificatesFrom, Int32 regenerateNotSelfSignedCertificatesTo, CloudServerStatus statuses, Int32 regenerateCertificateExiredInDays, String appBin, UInt16 sipPort, UInt16 tunnelPort, Nullable`1 httpPort, Nullable`1 httpsPort, Boolean isPassiveFailoverMode)
at PostInstall.CertificateGenerator.RenewCertificates(String appBin, String nginxConfigFolder, String configurationPath)
 
Do you have any software, other than 3CX, running on the system? Or have you modified any files manually?

This usually happens when one of those is applicable.
 
Thank you for your response. This is hosted on a dedicated vm in registered sip trunking partner data center. The path that is in error is not on our server it is at our subdomain at 3cx.us " ourdomain.ca.3cx.us failed -"
 
So you were asked if there was anything else running on the VM. The fact that it is hosted in a SIP trunking partner data center doesn't mean something else isn't on there. But that error is definitely on the VM. Are you responsible for managing the VM or is the registered SIP trunking partner's responsibility? Either way, it looks like something was modified outside of a normal 3CX/ISO install. So whoever manages the VM can fix the permissions or do a fresh install from the ISO.
 
  • Like
Reactions: Evolute IT
the file '/var/lib/3cxpbx/Bin/nginx/conf/Instance1/dhparam.pem'
must be owned by the user "phonesystem" if this has been changed, by any unnormal means, then you have the issue described. You need to find someone with SSH access to the underlying host to correct the issue.
 
Thanks, we are running a test on 3cx at the suggestion of the sip partner where we also have alternate servers working. My inquiry to their tech support replied with 3cx problem not vm management problem so I took that at face value. I will respond back to them as the vm configuration is there problem if it is an administation problem via the gui then it is ours.
 
Last edited:
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,982
Messages
590,120
Members
164,909
Latest member
Jacob.Ive