Custom FQDN, LetsEncrypt, and Linux Appliance

Status
Not open for further replies.

tmrazek

Customer
Joined
Jun 18, 2019
Messages
5
Reaction score
0
Currently, I'm setting up our 3CX system to use a custom FQDN, and want to use LetsEncrypt to automatically update the certs. Is this possible with the appliance or will I need to switch to a manually maintained linux box? I just dont want to have to remember to upload the new cert every 60 days.
 
this is currently not supported, if you want automatic certs, you need their fqdn
 
So easy to use 3CX embedded certificate process with LE, why not using this ?
 
  • Like
Reactions: Evolute IT
Appliance? Do you mean their ISO? Absolutely you can do it, it just has to be done outside of 3CX.
 
We were looking into the Custom FQDN as we like to have control of our certificates and having the ability to have more access to troubleshoot if there are issues. Esp with the 90 day expiring timeline, leaving that into someone else hands worries us a bit. Having that maintained in house, and informing me when a renew fails would be helpful. As this is my first system, are we notified if a renewal fails? and what are we able to do for resolution?
 
There is no "person" to rely on, it is all autonomous, the 3CX Server renews the certificate itself as needed, directly via letsencrypt, its not being done by 3CX staff, it is 100% automatic. Trust me, managing these certs in house when you get a lot of servers going, will be a giant headache, also, you can set the servers to notify you on renewal, and other cert events. We have NEVER had one of our servers fail to renew its own certificate, and we have literally 100+ 3cx servers...

IF a cert were to fail to renew for some unknown reason, there are 2 remediation methods.
  1. run a command on the shell to renew it manually.
  2. Reboot the server and usually, if its expired when it boots, it will renew itself shortly after reboot.
 
  • Like
Reactions: tmrazek
never got any failure in 3cx/ LE cert process renewal, all is done alone , you receive notification when done
 
  • Like
Reactions: tmrazek
There is no "person" to rely on, it is all autonomous, the 3CX Server renews the certificate itself as needed, directly via letsencrypt, its not being done by 3CX staff, it is 100% automatic. Trust me, managing these certs in house when you get a lot of servers going, will be a giant headache, also, you can set the servers to notify you on renewal, and other cert events. We have NEVER had one of our servers fail to renew its own certificate, and we have literally 100+ 3cx servers...

IF a cert were to fail to renew for some unknown reason, there are 2 remediation methods.
  1. run a command on the shell to renew it manually.
  2. Reboot the server and usually, if its expired when it boots, it will renew itself shortly after reboot.
We are looking at LE for our public web server now, and becuase it's automatic is why we are looking at it. I understand there isn't a 'person' doing the renewal. My concern was just in the instance that the renewal doesn't work, what are my available troubleshooting methods. As far as the command, are they running certbot, or another application to manage it?
 
i believe theirs is custom, search this forum and you can find it.
 
  • Like
Reactions: tmrazek
So the fact that it's 90 days vs 365 days or however long you would get your customer cert is irrelevant. If you are worried about certificate expiration, then monitor it. You should be doing this anyways regardless if its a 3CX FQDN or custom. Then you'll have plenty of notice if it's not renewing properly.

I've had renewals fail occassionally but not to the point of expiration. If it fails it retries the next day and succeeds. As @BrenttG mentions, whether you are managing 100's of instances as a 3CX partner or if 3CX is simply one part of a larger infrastructure you manage it's nice to not have to worry about one additional piece. The biggest pain point with 3CX FQDN is the lack of control over when it renews which can cause disruptions for businesses that are 24/7 or at least use the PBX in what are typically 'off-hours' and the certificate renewal process restarted the services bringing the system down briefly. Update 3 beta changes that behavior to do a reload instead of a restart which resolves that issue.

We'll see what happens if/when they decide to use that same cert for TLS
 
  • Like
Reactions: Zol
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,933
Messages
589,817
Members
164,810
Latest member
astrobalaji