Solved Direct Routing: Private key and certificate do not match.

Status
Not open for further replies.

mazo

Customer
Basic Certified
Joined
Feb 15, 2022
Messages
2
Reaction score
1
Hello,
this is driving me crazy for the last couple of days: The teams integration won't accept the certificate+key pair. Looks like some others had this issue too but unfortunately without a solution.

Here is what I did:
1) Created a DNS a record teams-sbc.example.com with the a record set to an Azure hosted 3CX v18.0 (Build 314)
2) Created an RSA keyfile and a CSR
3) Checked the documentation for the required CA and decided to go with a domain validated RapidSSL.
3) Got the CSR signed by RapidSSL
4) Put the signed certificate, the intermediate and the root ca into one file
5) Uploaded both files and got error: Private key and certificate do not match.

First thing I checked was the keyfile matching the cert:
$ openssl x509 -noout -modulus -in cert2021chain.pem Modulus=A2077E9F93DA55DF3EBC316BE7D3F148EBD4740A9270E5A56367A561CF68137E012640352C913B5A57CE31B66FDE46D182C8E2B6BAFB629934192EC6310B77F3D39B99203BECFB05DC69057D9AFB8344AC5FAD66C747B7DBACF28C36F0CADD497B5E4B5D064200470DD016E2F7A4DCB1F531B705EA2391FF704E5A5198422E904925325C26CAC6495D3F13B4CF48253C36B2B37C3723AF1FABCCBDF5B67DD0A0915110C4A1C52088424136005A63FA11981AF956062777764E1F0CF1CFC20865B247F0E58FB7767CFF14AA12AA3D61C2612F8A6E3DD0662BCC400CFA0540058F2B3D89A79D3D3FE4EB6229EC9F499D7A0DC63E13BF6148D4BAA9D3FB8343DA7F

$ openssl rsa -noout -modulus -in cert2021key.pem Modulus=A2077E9F93DA55DF3EBC316BE7D3F148EBD4740A9270E5A56367A561CF68137E012640352C913B5A57CE31B66FDE46D182C8E2B6BAFB629934192EC6310B77F3D39B99203BECFB05DC69057D9AFB8344AC5FAD66C747B7DBACF28C36F0CADD497B5E4B5D064200470DD016E2F7A4DCB1F531B705EA2391FF704E5A5198422E904925325C26CAC6495D3F13B4CF48253C36B2B37C3723AF1FABCCBDF5B67DD0A0915110C4A1C52088424136005A63FA11981AF956062777764E1F0CF1CFC20865B247F0E58FB7767CFF14AA12AA3D61C2612F8A6E3DD0662BCC400CFA0540058F2B3D89A79D3D3FE4EB6229EC9F499D7A0DC63E13BF6148D4BAA9D3FB8343DA7F

Just to be safe, I've tried to encrypt and decrypt a message using these files:
Encryption:
$ openssl x509 -in cert2021chain.pem -pubkey -noout -outform pem >cert2021pubkey.pem $ echo “Hello World” >message.txt $ openssl rsautl -encrypt -in message.txt -pubin -inkey cert2021pubkey.pem -out encrypted.txt

Decryption:
$ openssl rsautl -decrypt -in encrypted.txt -inkey cert2021key.pem Hello World

Looks good to me. Next I've checked the certificate chain:
$ openssl crl2pkcs7 -nocrl -certfile cert2021chain.pem | openssl pkcs7 -print_certs -text -noout | grep -E "(Subject|Issuer):" Issuer: C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1 Subject: CN=teams-sbc.example.com Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA Subject: C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1 Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA Subject: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA

... and if this root is supported by Microsoft (which should not make any difference at this point but who knows what 3CX is verifying...)

$ openssl x509 -noout -fingerprint -sha256 -inform pem -in cert2021root.pem | tr -d ":" SHA256 Fingerprint=4348A0E9444C78CB265E058D5E8944B4D84F9662BD26DB257F8934A443C70161

I've visited https://ccadb-public.secure.force.com/microsoft/IncludedCACertificateReportForMSFT for a full list of supported CAs and searched for the fingerprint with success.

I've tried to convert between Windows and Unix formatting and with and without a newline behind the last --- but with the same outcome.

Seems someone with the same issue got lucky bit re-keying the certificate (https://www.3cx.com/community/threa...upload-the-correct-certificate-and-key.86751/) so I tried the same without luck.

This is cert2021chain.pem:
-----BEGIN CERTIFICATE----- MIIGiDCCBXCgAwIBAgIQA8NUr... -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIFUTCCBDmgAw... -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIDrzCCApegA... -----END CERTIFICATE-----
The order is certificate -> RapidSSL intermediate -> DigiCert root

This is cert2021key.pem:
-----BEGIN RSA PRIVATE KEY----- MIIE... -----END RSA PRIVATE KEY-----

Any ideas what I have missed / else I could try?
 
Hi!

To be honest, it looks like you've covered a lot of the common pitfalls. I'll send you a PM shortly.
 
If you open your Key file with a text editor and the starting line is -----BEGIN RSA PRIVATE KEY-----, then try converting your key from PKCS#1 format to PKCS#8 format with this openssl command:
Bash:
openssl pkcs8 -topk8 -inform PEM -outform PEM -nocrypt -in <CURRENT KEY FILE> -out <NEW KEY FILE>

After you do this, try importing the certificates again, this time though using the new file that was generated.
Also if you open the new Key file now with a text editor, it should start with -----BEGIN PRIVATE KEY-----.
 
  • Like
Reactions: mazo and Evolute IT
This is the solution - made my day, thanks! :)
 
  • Like
Reactions: NickD_3CX
Glad we could help!
 
Just to add 1 more note to this, starting from V18 U3 Beta onward, 3CX should be able to accept PKCS#1 Private Key formats (the ones that start with -----BEGIN RSA PRIVATE KEY-----), so this conversion should no longer be required in newer versions of 3CX.
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.