Certificate renewal error for *.3cx.com domain

Status
Not open for further replies.

LoMik812

Forum User
Joined
Oct 12, 2020
Messages
6
Reaction score
0
Hello!


Tell me how you can fix this error?

------------------
SSL Certificate renewal has been failed. Error: Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.


SSL Certificate renewal has been failed. Error: Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException: Запрошенная операция не поддерживается. at System.Security.Cryptography.CngKeyLite.SetKeyLength(SafeNCryptKeyHandle keyHandle, Int32 keySize) at System.Security.Cryptography.CngKeyLite.GenerateNewExportableKey(String algorithm, Int32 keySize) at System.Security.Cryptography.DSAImplementation.DSACng.GetDuplicatedKeyHandle() at System.Security.Cryptography.DSAImplementation.DSACng.ExportKeyBlob(Boolean includePrivateParameters) at System.Security.Cryptography.DSAImplementation.DSACng.ExportParameters(Boolean includePrivateParameters) at PostInstall.CertificateUtils.DsaToDhParams(DSA dsa) at PostInstall.CertificateGenerator.GenerateDhParam() at PostInstall.CertificateGenerator.ProcessCertificatesDirectory(String directory, Boolean temporaryCertificateGenerated, Int32 regenerateNotSelfSignedCertificatesFrom, Int32 regenerateNotSelfSignedCertificatesTo, CloudServerStatus statuses, Int32 regenerateCertificateExiredInDays, String appBin, UInt16 sipPort, UInt16 tunnelPort, Nullable`1 httpPort, Nullable`1 httpsPort, Boolean isPassiveFailoverMode) at PostInstall.CertificateGenerator.RenewCertificates(String appBin, String nginxConfigFolder, String configurationPath)
Event Notification Manager ID: 50011 11.10.2020 0:18:5
 
Yes I'm getting the same but for a 3cx.co.uk domain.

Message I have got it is:-

The SSL Certificate renewal for ********.3cx.co.uk failed - Max certificate limit Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.
 
I have most people on Raspberry Pi SBC as the majority are home working at this time. I'm getting concerned that if this is not fixed then all my remote extensions will not work as happened before a few years ago and 3CX ended up compensating customers!

3CX please respond asap
 
Hi guys,

There limits to the number of allowed requests as per the message.

So just to confirm, did you reinstall your PBX recently or tried to force certificate renewal manually before you saw that message?
 
I didn’t reinstall 3cx and didn’t try to renew the certificate, the error occurred on its own.
Three months ago, the certificate was renewed without errors in automatic mode.
 
There have been no major changes with my setup either.

The only contact recently with 3CX was case 672777 regarding 3CX Partner Program and that I had to spin up a hosted instance to keep my status - this I did as requested by Paul Clark. I don't think this has anything to do with it as the hosted instance has a different name.

I think this may be a 3CX issue as I've seen a few people with SSL issues recently in the forums.
 
It appears there was some maintenance on Let's Encrypt recently, so anyone facing issues should allow their PBX another 24 hours to retry automatically and we should see whether it works now
https://statusgator.com/services/lets-encrypt
 
Still failing SSL renewal - this was received 5am this morning


The SSL Certificate renewal for **********.3cx.co.uk failed - Error:

Internal.Cryptography.CryptoThrowHelper+WindowsCryptographicException: The requested operation is not supported.

at System.Security.Cryptography.CngKeyLite.SetKeyLength(SafeNCryptKeyHandle keyHandle, Int32 keySize)

at System.Security.Cryptography.CngKeyLite.GenerateNewExportableKey(String algorithm, Int32 keySize)

at System.Security.Cryptography.DSAImplementation.DSACng.GetDuplicatedKeyHandle()

at System.Security.Cryptography.DSAImplementation.DSACng.ExportKeyBlob(Boolean includePrivateParameters)

at System.Security.Cryptography.DSAImplementation.DSACng.ExportParameters(Boolean includePrivateParameters)

at PostInstall.CertificateUtils.DsaToDhParams(DSA dsa)

at PostInstall.CertificateGenerator.GenerateDhParam()

at PostInstall.CertificateGenerator.ProcessCertificatesDirectory(String directory, Boolean temporaryCertificateGenerated, Int32 regenerateNotSelfSignedCertificatesFrom, Int32 regenerateNotSelfSignedCertificatesTo, CloudServerStatus statuses, Int32 regenerateCertificateExiredInDays, String appBin, UInt16 sipPort, UInt16 tunnelPort, Nullable`1 httpPort, Nullable`1 httpsPort, Boolean isPassiveFailoverMode)

at PostInstall.CertificateGenerator.RenewCertificates(String appBin, String nginxConfigFolder, String configurationPath)
 
Hi @numerii where is this machine hosted and what OS is it running on exactly?

and what version is the PBX exactly?
 
error repeated:

  • SSL Certificate renewal has been failed. Error: Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.
    Event Notification Manager ID: 50011 16.10.2020 6:11:28
  • SSL Certificate renewal has been failed. Error: Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.
    Event Notification Manager ID: 50011 16.10.2020 0:10:49


ProductStandard Annual
Version Number16.0.655
License Expires31.12.2022 0:00:00
 
What OS is your PBX running on @LoMik812 ?
 
Server 2008 is no more supported OS
 
Last edited:
Is there any workaround without reinstalling Windows? Maybe install an update or apply a patch?
 
No unfortunately, this is downright an unsupported OS. The last version to support it was V14 from 4 years ago so it's not just a simple matter of patching as many things have changed inside the PBX.

If you want to keep that OS for any reason, you can setup a VM on it and deploy our Debian ISO so the PBX will run in a supported environment at least.


3CX is tested and supported to run as a Virtual Machine on these hypervisor platforms:
  • VMware vSphere Hypervisor (ESXi) 6.X and above.
  • Microsoft HyperV 2012 R2 and above - see our Hyper-V Page for required settings.
  • KVM 2.8 and above
  • Citrix XenServer 7.0 and above
 
Ok thanks I'm running the same OS but was planning on upgrading - I'll move my upgrade plans forward then. Many thanks!!
 
In addition to renewing the certificate, what problems can arise with 3CX in the future if you leave it running on a Windows 2008 server?
 
Apple PUSH for iOS users does not work, but beyond that I have to say it's unknown..

We do not test that OS so any issues that would normally be "caught" during Quality Assurance testing, will not be found by us, they will be found by you instead (which is always unpleasant).

If you report those issues to us the only advice we will be able to offer at that point is that you need to upgrade to a supported OS before we can provide assistance.

On top of that, there is the more important factor that the OS is no longer supported even by the manufacturer, so there may be potential security flaws or incompatibilities (especially on TLS ciphers) that will not be addressed.
 
Status
Not open for further replies.

Forum statistics

Threads
111,993
Messages
590,178
Members
164,933
Latest member
bunthoeun.may