Configuring Yealink Phones to Use TLS

Status
Not open for further replies.

Mike Hammett

Customer
Basic Certified
Joined
May 18, 2018
Messages
254
Reaction score
43
The page: https://www.3cx.com/docs/secure-sip/

Says:
  1. Go to “Security” > “Trusted Certificates”. Click the “Browse” button and upload the client certificate, e.g. “root_cert_3CXPHONE.pem”.

Where do I find root_cert_3CXPHONE.pem?
 
Realistically, if you don't know, you shouldn't be configuring it. Wait for 3CX to have everything baked in so you don't have to ask these questions and it's one click. I have a feeling that will make an appearance this year (2nd half) if all goes well.

But seriously, is this an academic exercise or do you have some sort of compliance target you're trying to accomplish?

Hint.. the answer is actually very simple. You can ask whoever is issuing your SSL certificate. People tend to overthink VoIP.
 
Realistically, if you don't know, you shouldn't be configuring it. Wait for 3CX to have everything baked in so you don't have to ask these questions and it's one click. I have a feeling that will make an appearance this year (2nd half) if all goes well.

But seriously, is this an academic exercise or do you have some sort of compliance target you're trying to accomplish?
Attempting to work around Comcast, Frontier and others screwing with my traffic. Currently I buy and deploy Mikrotik routers for each of my client's work from home employees. That's not ideal.
 
I would do a SBC instead. A Pi is close to the price of a cheap Mikrotik or you could static IP the computer and use the Windows SBC with the caveat that the computer has to be on for the phone to work. Otherwise I'd try TCP first.


But if you really want to go the TLS route, are you using the 3CX FQDN?
 
I would do a SBC instead. A Pi is close to the price of a cheap Mikrotik or you could static IP the computer and use the Windows SBC with the caveat that the computer has to be on for the phone to work. Otherwise I'd try TCP first.


But if you really want to go the TLS route, are you using the 3CX FQDN?
SBCs aren't sustainable in a work from home environment. They cost more the the phone being deployed.

A Pi (as a 3CX SBC) is 50% more expensive than the hap ac^2 we're using and much less useful.

I'm using custom FQDNs and Thawte 123 certs with Yealink phones.
 
I guess it's a matter of what you want to support. We do Pi's (or windows SBC) for WFH and now push folks towards soft clients.

For 3rd party cert, simply look for the instructions you received when you got the certificate. Every provider I've used has a link to the root certificate. It's also generally available in their support section.
 
So just the root cert is all? I got the impression it was something special to 3CX or the phone, given the example filename.
 
Nope. As I said, people tend to over think it because it's VoIP. In the end, 3CX is a web server and the phone is a web client (browser). Except the phones don't have all the root certificates baked in because they have limited space. So if you used the 3CX FQDN, the LE root cert is already present in supported phones on supported firmware. For all others, if you didn't use a cert in 3CX that already had the root in the phone you have to load it.
 
Oh, so then if you already have certificates that the phone supports, that step would be unnecessary.

I hope to test this today.
 
I don't know if it works around Comcast yet, but I have been successful in setting up SIP over TLS on both the lab PBX (with a Let's Encrypt certificate) and the office PBX (with a traditional certificate). I'm working to make it more user-friendly and supportable.

It was dead simple.
 
You mention working around Comcast. Are you having occasional issues as can happen with STUN, or is it outright blocked?
 
Once it stops working at a given location, it never works again. Well, "never" long time... months and months.

It's almost all Comcast with the problems. I've heard of Frontier doing similar things.

No issues with any of the local providers, enterprise providers, etc.

It may not even be intentional on the network, it may just be screwed up router firmware that I don't have time to troubleshoot.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK