Solved Certificate not renewing

Status
Not open for further replies.

cam

Customer
Joined
Apr 3, 2019
Messages
128
Reaction score
18
Hi, I am testing a 3cx system and it looks like my certificate is not auto renewing.

It is locally hosted on Debian and I have a FQDN form 3cx i.e. xxxxx.3cx.co.uk

I have a maintenance contract and do not get notified of any failed updates so not sure if it is attempt's to update.
 
Hi,
Is it default 3CX installed certificate from LE ? if so , if automatic renewal failed wait 24h, it will try to renew alone.
 
Hi, sorry for the confusion but the data on the certificate is OK, however Chrome states the admin console is unsecure and certificate invalid.
 
is your computer date and time correct?
 
Yes its correct on my PC and on Debian server
 
if not already done try to refresh browser cache, or try with another browser FF or Opera
did you try with another computer and same browser ?
Did you made some change like antivirus, network settings?
 
Last edited:
OK in Firefox is states the certificate is for my FQDN when I am using my internal IP address as the FQDN wont work internally.
 
Do you use an URL with https://www.xxxxxx.3cx.co.uk or without www ?
Do you use a proxy?

With local IP, should be http:// IPBX-IP:5000/#/login
 
Ok so there is no problem. The certificate is issued to your FQDN correctly as you state but since you are accessing your PBX via IP address there is a mismatch and the browser is throwing an error (as it should). You have three options:

  • Use the http URL instead of the https URL internally
  • Add an entry in your local DNS server (if using one) to resolve your 3CX FQDN to the internal IP address
  • Check your router settings. It could something as simple as you haven't port forwarded the HTTPS port on your router. This is required because your 3CX FQDN by default would resolve to the WAN IP of your router. If you do have the port forwarding in place and can confirm you can access 3CX from outside then you need to check your router to see if you can enable NAT loopback/hairpin NAT.
 
  • Like
Reactions: cam and JohnS_3CX
Hi @cam

If you access the webclient without HTTPS and 5001, you will lose the audio. Only CTI mode will be available to you (thats only if the user has a deskphone) otherwise no calls can be made.

10758

You should either access the system from the FQDN directly, to avoid certificate errors (https://example.3cx.com:5001/webclient)

or

You should access the system using HTTPS and 5001 using the local IP address but you will have
certificate errors, the certificate does not understand IPs it only understands FQDNs.
(https://x.x.x.x:5001/webclient)
 
  • Like
Reactions: cam
Thanks John, I resolved this by creating an internal DNS entry https://www.3cx.com/docs/creating-fqdn-split-dns/

And updating line 53 of the Extension Welcome email so the link was the public name:

If in the office go to <a href="%%WEBCLIENTURLPUBLIC%%" target="_blank">%%WEBCLIENTURL%%</a>

Can you mark this as resolved.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,925
Messages
589,757
Members
164,798
Latest member
Call_Flow.co.uk