Solved How do you get the 3CX Windows app (softphone) to accept a root certificate to use TLS/SRTP

Status
Not open for further replies.

RichardBaker

Free User
Joined
Oct 23, 2019
Messages
4
Reaction score
2
I am using V16 3CX Server and V16 windows app.
I can set the Windows app to TLS/Secure but how do you load the root certificate.
The 3CX server has the Certificate and Key already loaded which has been proven to work with another device.
I have used a V6 app before and that allows you to manually add the Root certificate but I do not see the same thing in the V16 app
Thoughts please?
 
Hi Richard,

If you use a custom FQDN with your own certificate, you need to import it into Windows so it can communicate with your server.

Once that's done, all your windows apps that want to connect to your server (Desktop client, or Webclient) should be able to authenticate.

You can take a look at this guide if you are on a Windows 10 pc, and then provision your client normally as per 3CX instructions

https://docs.microsoft.com/en-us/skype-sdk/sdn/articles/installing-the-trusted-root-certificate
 
John, Thanks, I am nearly there but I am using a locked down work laptop. Now I know what to do I will get it sorted. KR
 
  • Like
Reactions: JohnS_3CX
By the way, if your custom certificate is not self-signed, Windows trusts it if it comes from a Root CA.

But if custom, then you will have to install it on any PC that will use the PBX
 
John,
Thanks and noted
Learning all the time (certificates are painful)
KR
 
I know painful, and an additional cost. Plus you need to maintain them too before they expire.

As part of the package, your 3CX system gives you an FQDN and Let's Encrypt certificates that automatically renew from the PBX - no interaction from the admin is needed, no setup, and no hassle, no additional cost. Remote STUN phones that are currently supported by 3CX also trust Let's Encrypt so that's another thing you don't have to worry about in case you ever use remote phones.

If you can avoid using custom certs, this takes care of a lot of hassle for you but I understand this is not possible in all cases, some organizations need to work with custom or self signed certs.
 
JohnS, Many thanks for your help/support with this, apologies for the delay in responding. It has been much appreciated and I am now connected using a 3CX soft-phone from a windows laptop. (With self signed certificates) I also needed to use a soft-phone from an iPhone and your help assisted me with that as well. (well gave me a good clue)
Currently this 3CX system is only being used for testing and not on alive connection but I will bear in mind your last message
Thank you
 
  • Like
Reactions: JohnS_3CX
You're welcome Richard, glad to assist ;)
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur