Solved Certificate error Yealink?

Status
Not open for further replies.

Paultechnica

Platinum Partner
Advanced Certified
Joined
Feb 4, 2020
Messages
26
Reaction score
4
Hi all

Is anyone having troubles autoprovisioning yealink IP phones?
 
  • Like
Reactions: OlivierD and JTW
You need to remove it from the Webserver ssl cert. not sure if you can access that on a 3CX cloud instance.
Would require ssh/console access to modify the file, then reload the nginx service to reload the Webserver
This worked for us, just tested with one customer.
 
This worked for us, just tested with one customer.
Hi Olivier,

Can you show us the way you managed to make it work again?

Thx in advance
 
We removed the LE ISRG Root X1 cert in both the instance and the GUI under Security Settings -> Secure SIP and restarted the Nginx service.
 
We removed the LE ISRG Root X1 cert in both the instance and the GUI under Security Settings -> Secure SIP and restarted the Nginx service.
Glad it works for you. But I tried that and it doesn't resolve it for me. What version 3CX are you using?
 
Glad it works for you. But I tried that and it doesn't resolve it for me. What version 3CX are you using?
Did you remove it in the instance aswell? We had to go into the Linux and remove it there. We have customers on both V16 and V18, we tested it on V16 but i don't think it's version related.
 
Did you remove it in the instance aswell? We had to go into the Linux and remove it there. We have customers on both V16 and V18, we tested it on V16 but i don't think it's version related.
I think so. I deleted the certificate located in /usr/share/ca-certificates/mozilla and issued the command update-ca-certificates --fresh. Afterwards I restarted the ngnix service in 3CX.
 
What @OlivierD suggests should work but please be patient while we come up with a solution and don't attempt any manual settings.
 
  • Like
Reactions: TechnicaICT
I'd like to follow, experiencing the same issues, Hopefully there will be a solution shortely.
 
Just as a point of interest, we have a mixture of T40G and T46S phones. I have tested a number of each and it would seem that the T40G phones fail when attempting to update the phonebook (unless I have manually disabled 'Only Accept Trusted Certificates', whereas the T46S phones are updating the phonebook without error.
 
Just as a point of interest, we have a mixture of T40G and T46S phones. I have tested a number of each and it would seem that the T40G phones fail when attempting to update the phonebook (unless I have manually disabled 'Only Accept Trusted Certificates', whereas the T46S phones are updating the phonebook without error.
Yes that is correct as the T46s have newer certificates in their firmware which solve this issue. We are working on solution for older devices that do not have a firmware update that solves this issue
 
I think so. I deleted the certificate located in /usr/share/ca-certificates/mozilla and issued the command update-ca-certificates --fresh. Afterwards I restarted the ngnix service in 3CX.


Modify your CRT file.
Linux: /var/lib/3cxpbx/Bin/nginx/conf/Instance1/<3cxdomain>-crt.pem
Windows: C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1/<3cxdomain>-crt.pem

Delete the 3rd certificate section. Then reload NGINX. Then run an ssl checker, and see how many certs its returning.
https://www.ssllabs.com/ssltest/analyze.html?d=3cxdomain&hideResults=on

3 - Bad.
1633356709034.png

2 - Good.
1633356739077.png
 
Last edited:
We are having this exact same issue with Yealink T29G's on firmware version 46.83.0.130 which is the latest available.
 
Probably any firmware that doesn't start with xx.86.x.x will give an issue. Either you do the manual change (not recommended by 3CX) or you wait untill 3CX fixes the issue. Seeing as this is a worldwide issue, this will have prio and be fixed very soon (hopefully :)).
 
I've attempted the manual fix, but backed up the cert and can restore it. if needs be when the proper fix arrives.

Thanks
 
We are having this exact same issue with Yealink T29G's on firmware version 46.83.0.130 which is the latest available.
Ouff
Modify your CRT file.
/var/lib/3cxpbx/Bin/nginx/conf/Instance1/<3cxdomain>-crt.pem

Delete the 3rd certificate section. Then reload NGINX. Then run an ssl checker, and see how many certs its returning.
https://www.ssllabs.com/ssltest/analyze.html?d=3cxdomain&hideResults=on

3 - Bad.
View attachment 24859

2 - Good.
View attachment 24860
This worked, thanks for the workaround and the example
 
Cross posting from our other thread, to confirm we have this on a Fanvil X4 with up to date firmware. Pcap from the phone shows 'bad certificate' after the hotdesk provisioning call has completed.
 
It partially did, in that it allowed a hotdesk phone to sign in. However the phone does not appear as being behind an SBC in the phones page, so not sure it is working correctly. Also, not sure if this is the same on the yealinks, but the system time on the phone itself is out by nearly two months. I know the time was correct on this phone last night as i set it manually.
 
Modify your CRT file.
Linux: /var/lib/3cxpbx/Bin/nginx/conf/Instance1/<3cxdomain>-crt.pem
Windows: C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1/<3cxdomain>-crt.pem

Delete the 3rd certificate section. Then reload NGINX. Then run an ssl checker, and see how many certs its returning.
https://www.ssllabs.com/ssltest/analyze.html?d=3cxdomain&hideResults=on

3 - Bad.
View attachment 24859

2 - Good.
View attachment 24860
Thx @cmp1 that did the trick for us.
@YiannisH_3CX Yes I understand that you guys are working on a solution, but we have a lot of customers using hotdesking that couldn't work properly for days now and we cannot wait any longer on a possible solution. This workaround is easy to undo after all devices are using the correct firmware.
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,368
Members
164,978
Latest member
FringeIT-Eric