HTTPS Certificate Renewal Failed

Status
Not open for further replies.

HFH-Digerati

Free User
Joined
Oct 30, 2020
Messages
31
Reaction score
3
I've started receiving alerts from the 3cx system (16.0.5.622 running on a physical on-prem Linux host) that the renewal of the SSL certificate has failed (below). This has been going on for about a week so it doesn't appear to be self-resolving. I am no longer able to get to the web management portal through <companyname>.3cx.us because of HSTS but can get to it locally at https://<ipaddress> which allows an exception.

HTTPS Certificate renewal Failed - Network problem
SSL certificate failed due to network conditions. Unable to reach Certificate Issuing Servers. The process to renew your certificate will start again in a couple of hours.

I've inherited the system but it appears to be running a default install with Let's Encrypt certs. I don't find anywhere in the web interface where I can view the cert. I've looked in the firewall and don't see any denies for traffic from the phone system.

TIA
 
Wondering if this has to do with the ruleset at the firewall. Found Dashboard > Firewall > Firewall Check which I'll run after hours. Might add an any port/any IP outbound rule from the PBX to see if this resolves the problem with the cert.
 
By ruleset in the firewall do you mean your firewall in front of 3CX or firewall on 3CX itself. There should be no firewall on 3CX itself, and the firewall checker is just to check if port forwarding is setup correctly. Your error is most likely caused by one of the following:

- Expired maintenance/license
- 3CX not being up to date
- Edge Firewall blocking access to LE infrastructure

I'd start by checking your license status and updated to Update 6.
 
Status
Not open for further replies.

Forum statistics

Threads
111,992
Messages
590,171
Members
164,929
Latest member
Cloudstar