Found 3CX server has SIP TLS Certificate file name mapping problem

Status
Not open for further replies.

ccwl

Free User
Joined
Jul 22, 2020
Messages
1
Reaction score
1
Hi, I've found some bug in SIP TLS Certificate file name mapping in my self-hosted 3CX trial system using 3CX FQDN setup (V16.0.5.619)
In the wizard, I'm entered case sensitive domain name e.g. Abcd-EFG.elastix.com, the system is working fine for TCP/UDP SIP also https web management get valid certificate.

However, SIP TLS registration from phone is not working which I noticed that there is "There's no valid Domain certificate/key for SIP domain" error, even there is certificate file "domain_cert_Abcd-EFG.elastix.com.pem" and "domain_key_Abcd-EFG.elastix.com.pem" in /var/lib/3cxpbx/Instance1/Bin/Cert folder.
Delete and add cert+key again from web management also doesn't help, the netstat result showing that 3CX server doesn't listen to SIP TLS TCP Port 5061.

As I recall that Linux has case sensitive file system, so I try to copy certificate file "domain_cert_Abcd-EFG.elastix.com.pem" and "domain_key_Abcd-EFG.elastix.com.pem" to "domain_cert_abcd-efg.elastix.com.pem" and "domain_key_abcd-efg.elastix.com.pem" into the same /var/lib/3cxpbx/Instance1/Bin/Cert folder.

After that I try to restart the 3CX service again, now 3CX server is listening to SIP TLS TCP Port 5061 and SIP TLS phone client can be now registered and make a call, Yeah!

I post this topic to share with other person who might get the same problem with me.

If 3CX support saw this post, Could you please proceed to fix this bug as I think my method is just a workaround which I don't sure when it come to certificate expire date and system has automatically renew the cert, do I've to copy those certificate to be in lower case file name again or not.
 
  • Like
Reactions: YiannisH_3CX
Hello @ccwl

We are already aware of the issue and we have applied a fix for the upcoming update 6 which is currently in Alpha.
Due to the nature of the issue though once the stable version comes out you will need perform a backup of the current system without including licence and FQDN and un-install the system. Then re-install the new version using your backup. This will fix the issue and SIP TLS will work without having to manually renaming the certificates.
 
  • Like
Reactions: ccwl
Status
Not open for further replies.

Forum statistics

Threads
111,955
Messages
589,925
Members
164,853
Latest member
as7h