- Joined
- May 4, 2020
- Messages
- 33
- Reaction score
- 7
We have a SIP trunk with an unsupported vendor using TLS. The vendor provided us with the root certificate which we uploaded and all outbound calls are fine. For inbound calls, it was working for serveral weeks then all of a sudden the 3CX server started rejecting the inbound TLS handshake requests (strangely enough it was a midnight Eastern time when the calls started failing...hmmm). A packet capture shows the Client Hello being sent to 3CX, which immediatly sends a RST, ACK without any sort of errors we can find. The offered ciphers seem fine. I know this implies an expired certificate, possibly, but we have another TLS SIP trunk with another vendor and it's working fine.
The question is what certificate is being used for INBOUND calls? Is it the same for all TLS trunks? Is it the one found in Security-Secure SIP settings or is it the one we place in C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1?
Thanks!
The question is what certificate is being used for INBOUND calls? Is it the same for all TLS trunks? Is it the one found in Security-Secure SIP settings or is it the one we place in C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1?
Thanks!