Solved 3CX V16 - TLS SIP Trunk - No Wildcard-Support?!

Status
Not open for further replies.

twindscheif

Customer
Advanced Certified
Joined
Jul 10, 2018
Messages
25
Reaction score
11
Hi there,

i'm trying to change my current SIP-Trunk to use TLS + SRTP.
Currently after change the registration fails immediately.
My SIP-Provider told me that he cannot see my registration request.

The Event-Log of 3CX states:
503 Certificate Validation Failure.

I already retrieved the Endpoint Certificate and the certificate chain via openssl and builded an DER-formatted PEM-File.
The file is readable and working. I uploaded the PEM to 3CX SIP-TRunk-setting.

But still after reboot of PBX no registration.

As stated here (https://www.3cx.com/community/threa...tificate-validation-failure.71997/post-321946) from 3CX staff Wildcard-certificate as endpoint certificates on SIP-Trunks are not supported?!

Could you please tell me why - in year 2020 - Wildcard-certificates are not supported?
It is a common type of certificate.

Is there any plan to add support for this or any "trick" to override the validation on 3CX?

Regards,
Thomas Windscheif
 
Which supported trunk provider are you trying to get this to work with?
 
My current provider is: Deutsche Telefon Standard.
Unfortunately 3CX removed Support for them with V16 silently, after DTS was bought by NFON ;).
Whether it is a supported trunk or not doesn't matter in my opinion. Nearly every service is using wildcard certificates, if this is the reason why the trunk doesn't connect, it's - in my opinion - a design bug of 3CX.

Regards,
Thomas
 
Dear @twindscheif I think you would like to pass this to DTS and we don't call it a 3CX bug...

RFC5922

7.2. Comparing SIP Identities


When an implementation (either client or server) compares two values
as SIP domain identities:

Implementations MUST compare only the DNS name component of each
SIP domain identifier; an implementation MUST NOT use any scheme
or parameters in the comparison.

Implementations MUST compare the values as DNS names, which means
that the comparison is case insensitive as specified by RFC 4343
[3]. Implementations MUST handle Internationalized Domain Names
(IDNs) in accordance with Section 7.2 of RFC 5280 [6].

Implementations MUST match the values in their entirety:

Implementations MUST NOT match suffixes. For example,
"foo.example.com" does not match "example.com".

Implementations MUST NOT match any form of wildcard, such as a
leading "." or "*." with any other DNS label or sequence of
labels. For example, "*.example.com" matches only
"*.example.com" but not "foo.example.com". Similarly,
".example.com" matches only ".example.com", and does not match
"foo.example.com".
 
  • Like
Reactions: twindscheif
OK, thats a word :).
I'll pass it to DTS. I already opened a ticket there and escalated the issue to dev.

Regards,
Thomas Windscheif
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,924
Members
164,852
Latest member
priya