Failed to send APNS PUSH to device - Internal exception occured: The SSL connection could not be established, see inner exception.

Status
Not open for further replies.

jncarter

Customer
Joined
Dec 25, 2021
Messages
6
Reaction score
3
  • 3CX Version: Enterprise Annual - 18.0 (Build 415)
  • Server OS: Debian GNU/Linux 10
  • Is the 3CX Server Hosted and where? AWS
  • Has the Firewall Checker passed: YES

I upgraded to v18 update 5 last night. Since then our users with the IOS app are no longer receiving phone calls through the app. When I look at the log, every time there is an incoming phone call, I see the following error:

Failed to send APNS PUSH to device iPhone11,8Tow’s iPhone(Ext.14). Internal exception occured: The SSL connection could not be established, see inner exception.

Firewall checker pashes, I tried a verbose curl of api.push.apple.com:443 and it says the certificate checks ok. Not sure what else to check.

For now I have changed those extensions using the iphone app to simultaneously ring the mobile which will work for now. Though it is a pain because we lose caller id...
 
I just have the same PBX build as you, 18.0.415 on Linux machine and push is working OK for iOS. Can you check the PBX push certificate version (/var/lib/3cxpbx/Instance1/Bin/Cert/Apple/version.txt usually) and paste it here?
 
Thanks! I'll check tomorrow morning with my teammates, it's past midnight here me I'm not the best person in troubleshooting PBX configuration.
 
  • Like
Reactions: jncarter
Sounds good, I appreciate the response (especially so late). Have a good evening and we can check in the morning.
 
Only one thing: "I tried a verbose curl of api.push.apple.com:443" - you did this from the PBX machine or from your computer? If you did from your computer, then I suggest to try, from the PBX machine, a telnet api.push.apple.com 443, see if it's working and let me know.
 
This is from the pbx.

* Trying 17.188.182.141...
* TCP_NODELAY set
* Expire in 149997 ms for 3 (transfer 0x56340cba80f0)
* Expire in 200 ms for 4 (transfer 0x56340cba80f0)
* Connected to api.push.apple.com (17.188.182.141) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: none
CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Request CERT (13):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Certificate (11):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384
* ALPN, server accepted to use h2
* Server certificate:
* subject: CN=api.push.apple.com; OU=management:idms.group.887777; O=Apple Inc.; ST=California; C=US
* start date: Dec 9 03:25:59 2021 GMT
* expire date: Jan 8 03:25:58 2023 GMT
* subjectAltName: host "api.push.apple.com" matched cert's "api.push.apple.com"
* issuer: CN=Apple Public Server RSA CA 12 - G1; O=Apple Inc.; ST=California; C=US
* SSL certificate verify ok.
* Using HTTP2, server supports multi-use
* Connection state changed (HTTP/2 confirmed)
* Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0
* Using Stream ID: 1 (easy handle 0x56340cba80f0)
> GET / HTTP/2
> Host: api.push.apple.com
> User-Agent: curl/7.64.0
> Accept: */*
>
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
* Connection state changed (MAX_CONCURRENT_STREAMS == 1)!
< HTTP/2 405
< apns-id: 1EFBBF14-B8A7-D964-2256-0F70B2AB0B5A
<
* Connection #0 to host api.push.apple.com left intact
 
  • Like
Reactions: Vali_3CX
Good morning
We'll need the PBX verbose logs containing such failed call and a failed chat message. Best advice is to open a ticket to our tech support so they can check the issue thoroughly. Anyway, if you prefer, you can send it to me and I will pass to them.

So
- in the Management Console be sure the PBX is in verbose logging (Dashboard/Activity Log/ Settings)
- lock the iOS client device
- make a call and send call to the iOS client (both would require APNS connection for PUSH)
- in the Management Console, on the very top bar, click the Support menu button and there chose Generate Support Info.

Once completed, the PBX will send you an eMail containing a link to zipped logs; put that zip on dropbox or google drive and send me the link by PM.

Thanks!
 
Thank you Vali. I have sent you a PM with a onedrive link to the zip.
 
Just following up on this. I had IPv6 enabled on the vm. Apparently one of Apple's servers was not responding properly on IPv6. I disabled it and forced IPv4. No issues after that.
 
Glad to hear - and thanks for feedback!
 
Hello,

It seems that this issue hasn't been completely solved yet...

A customer of ours notified us that they did not receive iOS push notifications anymore. Their PBX had the latest hotfix installed. We tested this and as it turns out, the latest hotfix breaks iOS push notifications to iphones. The 'Update 5' doesn't have this issue, only the hotfix does.

Kenneth
 
@Smart Connect
Hi Kenneth
I suggest you to open a ticket to our tech support - especially you being a Platinum Partner - so they can properly troubleshoot the PBX.
Thank you!
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage