How to regenerate SIP/TLS certificate for 3cx domain?

Status
Not open for further replies.

AndreC

Free User
Basic Certified
Joined
Feb 12, 2020
Messages
27
Reaction score
2
Hi all,

I lost my certificates that were generated at install time in the Secure SIP tab (#/app/settings/security/159/secure_sip).
How can I regenerate them?

It's a 3CX Provided FQDN and NOT a custom domain.

Is there a way to force trigger a new generation somehow?

Thanks
 
Are you actually using secure SIP and somethings not working?
 
On one account it all works with secure SIP but not on my other installation.
On the second installation I lost the certificate and private key as I had saved with the Secure SIP/TLS unchecked... that cleared everything unfortunately...

I now need to recover or recreate them...

I believe those are needed to allow a TLS connection to my SIP provider (VoIP.MS)
 
Basically 2 things I'm trying to achieve here.

1- Secure connection between 3CX (hosted in AWS LightSail) and VOIP.MS
2- Secure connection between 3CX and phones (3CX for iOS, Grandstream, Yealink, Chrome Extension, Mac and Windows desktop clients).
 
Basically 2 things I'm trying to achieve here.

1- Secure connection between 3CX (hosted in AWS LightSail) and VOIP.MS
2- Secure connection between 3CX and phones (3CX for iOS, Grandstream, Yealink, Chrome Extension, Mac and Windows desktop clients).
1. Use TLS if Voip.ms supports it (I think they do)
2. If you use the SBC for your phones, you're already secured. The softphone apps (Windows, Mac, Web, and mobile) all uses the tunnel too, just like the SBC, so you are encrypted there as well.
 
VOIP does support TLS as I have it on one account.
I cannot get it to work on 2 other accounts (still investigating)

As for secure... what is the purpose of the Secure SIP certificates if they are not needed for any config? I can simply uncheck it and leave all blank?? I'm confused here..

As for phones;;
3CX app on iOS: SIP Transport: UDP, Use 3CX Tunnel for remote connection: Checked

Yelling T23G: Direct SIP (STUN - remote) no other settings there..

Global
SSL/SecureSIP Transport and Ciphers : Checked
Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system)

Secure SIP/TLS: unchecked and both box empty

I that mean that that all my phones are secure between the phones and the remote 3CX ?
 
The Secure SIP section is for phones. Not trunks.

It is used when you need SIP TLS (port 5061) in STUN. The Tunnel (SBC & apps) makes that useless since it has its own encryption.

You can leave it unchecked and empty. On a new install, those fields are prefilled with the certificate created at install.
 
If you want your Yealink phone to be secured, spin up and SBC and use it instead of STUN.

As of now, 3CX doesn't officially support Secure SIP and cannot provision it. You have to manually do the setup, which is wayyyy more complicated than running a Pi or miniPC with SBC on it.
 
  • Like
Reactions: JohnS_3CX
Do you have a way to regenerated the certificates that were generated at install time?
from the doc I seem that I still need them to use TLS.
Im still not sure about the SBC setup here.. it seem that since the 3CX is remote I would need to add another device on the lan to support this..
 
Do you have a way to regenerated the certificates that were generated at install time?
from the doc I seem that I still need them to use TLS.
Yes, the certificate is needed if you want to use Secure SIP. See the link provided by @cobaltit. However, as mentionned above, the SBC doesn't use Secure SIP but a proprietary encryption.


Im still not sure about the SBC setup here.. it seem that since the 3CX is remote I would need to add another device on the lan to support this..
Indeed, you would need a PC or Raspberry Pi 3B+ to use the SBC. But I strongly recommend it. It fixes a lot of issues as well as provide: local calling direct between phones (if no recording enabled), multicast forwarding to the PBX (so new phones appear automatically) and also statistics and notifications in the 3CX Console.

See https://www.3cx.com/docs/3cx-tunnel-session-border-controller/ for details.
 
Yes, the certificate is needed if you want to use Secure SIP. See the link provided by @cobaltit. However, as mentionned above, the SBC doesn't use Secure SIP but a proprietary encryption.



Indeed, you would need a PC or Raspberry Pi 3B+ to use the SBC. But I strongly recommend it. It fixes a lot of issues as well as provide: local calling direct between phones (if no recording enabled), multicast forwarding to the PBX (so new phones appear automatically) and also statistics and notifications in the 3CX Console.

See https://www.3cx.com/docs/3cx-tunnel-session-border-controller/ for details.

I'll can ask my client if he want to invest in an extra device..
They only have 4 phones and maybe one more later.. so very small setup which is already working. Just not sure if the connections between the phones and the 3CX are secure as I have found no way of confirming this.


As for the link provided by @cobaltit I tried but could not validate the newly generated certificate as I do not control my3cx.ca domain to add any entries..
 
I'll can ask my client if he want to invest in an extra device..
They only have 4 phones and maybe one more later.. so very small setup which is already working. Just not sure if the connections between the phones and the 3CX are secure as I have found no way of confirming this.


As for the link provided by @cobaltit I tried but could not validate the newly generated certificate as I do not control my3cx.ca domain to add any entries..
I can tell you right now that no, the phones are not secured in this case. However, since you have 4 phones, I STRONGLY recommend the SBC because in STUN, the more devices you add, the more trouble you get. A MiniPC for the SBC can cost less than 100$ and save MANY hours of work, so the value is there.
 
I can tell you right now that no, the phones are not secured in this case. However, since you have 4 phones, I STRONGLY recommend the SBC because in STUN, the more devices you add, the more trouble you get. A MiniPC for the SBC can cost less than 100$ and save MANY hours of work, so the value is there.

Will this require any special configuration on the router? I have absolutely no control over the router..
 
Will this require any special configuration on the router? I have absolutely no control over the router..
No. STUN does require port forwarding, SBC doesn't. It eliminates a lot of headaches.
 
No. STUN does require port forwarding, SBC doesn't. It eliminates a lot of headaches.

all phones currently works without any port forwarding or any sort of router changes... and I'm using Direct SIP (STUN-remote)...

Do you have a any suggestion for a SBC that would be more around $35-50 at max? They are currently on a very tight budget, maybe down the road they will have the $$...
that is why I was trying to set them up using built in tools, that works for my setup at home using TLS but on their install I have lost the certificates and cannot find regenerate
 
hi,

I have tried but still cannot pass the validation to be able to download a new certificate.
Note that I am using a 3CX generated domain (xxx.my3cx.ca)

Any suggestions?
Create a full backup. Destroy the instance then recreate. It should create the new SSL on restoring the backup.
 
Create a full backup. Destroy the instance then recreate. It should create the new SSL on restoring the backup.

I was afraid of this... my very last choice... Just too bad there's no way to just trigger a regenerate of the certificates..
Problem with this is that I won't be able to remotely reconnect their phones...
 
I've looked at SBC and unfortunately it does not run on Debian-jessie... so I will need to get a new device.. I was hoping to be able to use my old C.H.I.P. device... oh well
 
Status
Not open for further replies.

Forum statistics

Threads
112,036
Messages
590,406
Members
164,989
Latest member
Michael Wallisch