You need to add the issuer (and any intermediates, but unlikely) to the Root CA store. And if you have an intermediate cert, it must be present in the chain on the bitrix server.I have a customer using self signed certs for his self hosted Bitrix24 installation. When I click on test I get a SSL error
View attachment 40745
Which root CA do I add to which server?
They could do DNS validation without worrying about this.There is one potential gotcha however... you must have a valid resolvable FQDN you can assign to the Bitrix server (at least for the required ports) that Let's Encrypt can use to verify your ownership of the FQDN (needed to obtain a certificate). It is not hard to accomplish the verification if you have basic knowledge on how to open ports on the firewall. Once the verification is complete, you can close the verification port (TCP 80) and never worry about this again.
Absolutely true. I always debate which is easier, updating the DNS or briefly opening port 80. I usually go with port 80 since I rarely have access to the customer's DNS server.They could do DNS validation without worrying about this.
a 3CX FQDN won't solve the SSL/FQDN of the Bitrix install they haveYou may also consider using a 3CX FQDN to avoid this situation.
Yes it would be nice if they used real FQDN but no, they want to use .localI think the error provides the answer "The remote certificate is invalid because of errors in the certificate chain". Yeah, that's the problem with a self-signed certificate.
In the era of free SSL certificates from Let's Encrypt and others, help your customer convert to a "real" certificate. We use "Certify the Web" for automating the creation and renewal of certs on Windows, and Certbot on Linux. It's easy to do, free, and it eliminates the issues with self-signed certificates.
There is one potential gotcha however... you must have a valid resolvable FQDN you can assign to the Bitrix server (at least for the required ports) that Let's Encrypt can use to verify your ownership of the FQDN (needed to obtain a certificate). It is not hard to accomplish the verification if you have basic knowledge on how to open ports on the firewall. Once the verification is complete, you can close the verification port (TCP 80) and never worry about this again.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.