- Joined
- Feb 15, 2022
- Messages
- 2
- Reaction score
- 1
Hello,
this is driving me crazy for the last couple of days: The teams integration won't accept the certificate+key pair. Looks like some others had this issue too but unfortunately without a solution.
Here is what I did:
1) Created a DNS a record teams-sbc.example.com with the a record set to an Azure hosted 3CX v18.0 (Build 314)
2) Created an RSA keyfile and a CSR
3) Checked the documentation for the required CA and decided to go with a domain validated RapidSSL.
3) Got the CSR signed by RapidSSL
4) Put the signed certificate, the intermediate and the root ca into one file
5) Uploaded both files and got error: Private key and certificate do not match.
First thing I checked was the keyfile matching the cert:
Just to be safe, I've tried to encrypt and decrypt a message using these files:
Encryption:
Decryption:
Looks good to me. Next I've checked the certificate chain:
... and if this root is supported by Microsoft (which should not make any difference at this point but who knows what 3CX is verifying...)
I've visited https://ccadb-public.secure.force.com/microsoft/IncludedCACertificateReportForMSFT for a full list of supported CAs and searched for the fingerprint with success.
I've tried to convert between Windows and Unix formatting and with and without a newline behind the last --- but with the same outcome.
Seems someone with the same issue got lucky bit re-keying the certificate (https://www.3cx.com/community/threa...upload-the-correct-certificate-and-key.86751/) so I tried the same without luck.
This is cert2021chain.pem:
The order is certificate -> RapidSSL intermediate -> DigiCert root
This is cert2021key.pem:
Any ideas what I have missed / else I could try?
this is driving me crazy for the last couple of days: The teams integration won't accept the certificate+key pair. Looks like some others had this issue too but unfortunately without a solution.
Here is what I did:
1) Created a DNS a record teams-sbc.example.com with the a record set to an Azure hosted 3CX v18.0 (Build 314)
2) Created an RSA keyfile and a CSR
3) Checked the documentation for the required CA and decided to go with a domain validated RapidSSL.
3) Got the CSR signed by RapidSSL
4) Put the signed certificate, the intermediate and the root ca into one file
5) Uploaded both files and got error: Private key and certificate do not match.
First thing I checked was the keyfile matching the cert:
$ openssl x509 -noout -modulus -in cert2021chain.pem
Modulus=A2077E9F93DA55DF3EBC316BE7D3F148EBD4740A9270E5A56367A561CF68137E012640352C913B5A57CE31B66FDE46D182C8E2B6BAFB629934192EC6310B77F3D39B99203BECFB05DC69057D9AFB8344AC5FAD66C747B7DBACF28C36F0CADD497B5E4B5D064200470DD016E2F7A4DCB1F531B705EA2391FF704E5A5198422E904925325C26CAC6495D3F13B4CF48253C36B2B37C3723AF1FABCCBDF5B67DD0A0915110C4A1C52088424136005A63FA11981AF956062777764E1F0CF1CFC20865B247F0E58FB7767CFF14AA12AA3D61C2612F8A6E3DD0662BCC400CFA0540058F2B3D89A79D3D3FE4EB6229EC9F499D7A0DC63E13BF6148D4BAA9D3FB8343DA7F$ openssl rsa -noout -modulus -in cert2021key.pem
Modulus=A2077E9F93DA55DF3EBC316BE7D3F148EBD4740A9270E5A56367A561CF68137E012640352C913B5A57CE31B66FDE46D182C8E2B6BAFB629934192EC6310B77F3D39B99203BECFB05DC69057D9AFB8344AC5FAD66C747B7DBACF28C36F0CADD497B5E4B5D064200470DD016E2F7A4DCB1F531B705EA2391FF704E5A5198422E904925325C26CAC6495D3F13B4CF48253C36B2B37C3723AF1FABCCBDF5B67DD0A0915110C4A1C52088424136005A63FA11981AF956062777764E1F0CF1CFC20865B247F0E58FB7767CFF14AA12AA3D61C2612F8A6E3DD0662BCC400CFA0540058F2B3D89A79D3D3FE4EB6229EC9F499D7A0DC63E13BF6148D4BAA9D3FB8343DA7FJust to be safe, I've tried to encrypt and decrypt a message using these files:
Encryption:
$ openssl x509 -in cert2021chain.pem -pubkey -noout -outform pem >cert2021pubkey.pem
$ echo “Hello World” >message.txt
$ openssl rsautl -encrypt -in message.txt -pubin -inkey cert2021pubkey.pem -out encrypted.txtDecryption:
$ openssl rsautl -decrypt -in encrypted.txt -inkey cert2021key.pem
Hello WorldLooks good to me. Next I've checked the certificate chain:
$ openssl crl2pkcs7 -nocrl -certfile cert2021chain.pem | openssl pkcs7 -print_certs -text -noout | grep -E "(Subject|Issuer):"
Issuer: C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1
Subject: CN=teams-sbc.example.com
Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
Subject: C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1
Issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
Subject: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA... and if this root is supported by Microsoft (which should not make any difference at this point but who knows what 3CX is verifying...)
$ openssl x509 -noout -fingerprint -sha256 -inform pem -in cert2021root.pem | tr -d ":"
SHA256 Fingerprint=4348A0E9444C78CB265E058D5E8944B4D84F9662BD26DB257F8934A443C70161I've visited https://ccadb-public.secure.force.com/microsoft/IncludedCACertificateReportForMSFT for a full list of supported CAs and searched for the fingerprint with success.
I've tried to convert between Windows and Unix formatting and with and without a newline behind the last --- but with the same outcome.
Seems someone with the same issue got lucky bit re-keying the certificate (https://www.3cx.com/community/threa...upload-the-correct-certificate-and-key.86751/) so I tried the same without luck.
This is cert2021chain.pem:
-----BEGIN CERTIFICATE-----
MIIGiDCCBXCgAwIBAgIQA8NUr...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFUTCCBDmgAw...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIDrzCCApegA...
-----END CERTIFICATE-----The order is certificate -> RapidSSL intermediate -> DigiCert root
This is cert2021key.pem:
-----BEGIN RSA PRIVATE KEY-----
MIIE...
-----END RSA PRIVATE KEY-----Any ideas what I have missed / else I could try?