- Joined
- Mar 18, 2020
- Messages
- 55
- Reaction score
- 10
Have a system running v18 - just updated to 18.03. Debian 10.
It started alerting a week or so back that SSL renewal had failed (3cx.co.uk address)
Only just got approval to look at it today.
Have installed the available updates, and debian updates. Rebooted.
Is there a way to run a manual SSL renewal?
Error in log is:
SL Certificate renewal has been failed. Error: SSL certificate failed due to network conditions. Unable to reach Certificate Issuing Servers. We�ll try again in a couple of hours.
From PBXConfigToolRenewCertificates.Log
2022/05/24 15:47:58.836|Dbg|0001| Connecting to PhoneSystem
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected = True (waittime=00:00:00.3353070)
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected(2) = True
2022/05/24 15:47:59.174|Dbg|0001| Parameter name: REGENERATE_CERTIFICATE_EXPIRED_IN_DAYS, value = 25
2022/05/24 15:47:59.174|Dbg|0001| Is temporary certificate generated = False
2022/05/24 15:47:59.174|Dbg|0001| regenerateFromStr = , regenerateToStr =
2022/05/24 15:47:59.174|Dbg|0001| SIPPORT port in PBX = 5060
2022/05/24 15:47:59.174|Dbg|0001| Using SipPort = 5060
2022/05/24 15:47:59.174|Dbg|0001| ENABLE_DNS_HELPER =
2022/05/24 15:47:59.174|Dbg|0001| TNL_CLIENT_LISTEN_PORT port in PBX = 5090
2022/05/24 15:47:59.174|Dbg|0001| Using TunnelPort = 5090
2022/05/24 15:47:59.213|Dbg|0001| Processing directory = /var/lib/3cxpbx/Bin/nginx/conf/Instance1, regenerateCertificateExiredInDays = 25, temporaryCertificateGenerated = False, regenerateNotSelfSignedCertificatesFrom = 0, regenerateNotSelfSignedCertificatesTo = 7, isPassiveFailoverMode = False, enableDnsHelper = False
2022/05/24 15:47:59.213|Dbg|0001| Real (not self-signed) certificates regenerates from 0 to 7 hour. Skip.
2022/05/24 15:47:59.213|Dbg|0001| Processing directory /var/lib/3cxpbx/Bin/nginx/conf/Instance1 completed
2022/05/24 15:47:59.213|Dbg|0001| Disconnecting from PhoneSystem
2022/05/24 15:47:59.216|Dbg|0001| Phone System disconnected
2022/05/24 15:47:59.216|Dbg|0001| Finish updating certificates. Updated 0 certificates
In the past we could use /usr/lib/3cxpbx/PbxConfigTool -renew-certificates but this is going back a few years.
I can ping activate.3cx.com, but i dont think it has tried to renew since the latest updates were applied.
It started alerting a week or so back that SSL renewal had failed (3cx.co.uk address)
Only just got approval to look at it today.
Have installed the available updates, and debian updates. Rebooted.
Is there a way to run a manual SSL renewal?
Error in log is:
SL Certificate renewal has been failed. Error: SSL certificate failed due to network conditions. Unable to reach Certificate Issuing Servers. We�ll try again in a couple of hours.
From PBXConfigToolRenewCertificates.Log
2022/05/24 15:47:58.836|Dbg|0001| Connecting to PhoneSystem
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected = True (waittime=00:00:00.3353070)
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected(2) = True
2022/05/24 15:47:59.174|Dbg|0001| Parameter name: REGENERATE_CERTIFICATE_EXPIRED_IN_DAYS, value = 25
2022/05/24 15:47:59.174|Dbg|0001| Is temporary certificate generated = False
2022/05/24 15:47:59.174|Dbg|0001| regenerateFromStr = , regenerateToStr =
2022/05/24 15:47:59.174|Dbg|0001| SIPPORT port in PBX = 5060
2022/05/24 15:47:59.174|Dbg|0001| Using SipPort = 5060
2022/05/24 15:47:59.174|Dbg|0001| ENABLE_DNS_HELPER =
2022/05/24 15:47:59.174|Dbg|0001| TNL_CLIENT_LISTEN_PORT port in PBX = 5090
2022/05/24 15:47:59.174|Dbg|0001| Using TunnelPort = 5090
2022/05/24 15:47:59.213|Dbg|0001| Processing directory = /var/lib/3cxpbx/Bin/nginx/conf/Instance1, regenerateCertificateExiredInDays = 25, temporaryCertificateGenerated = False, regenerateNotSelfSignedCertificatesFrom = 0, regenerateNotSelfSignedCertificatesTo = 7, isPassiveFailoverMode = False, enableDnsHelper = False
2022/05/24 15:47:59.213|Dbg|0001| Real (not self-signed) certificates regenerates from 0 to 7 hour. Skip.
2022/05/24 15:47:59.213|Dbg|0001| Processing directory /var/lib/3cxpbx/Bin/nginx/conf/Instance1 completed
2022/05/24 15:47:59.213|Dbg|0001| Disconnecting from PhoneSystem
2022/05/24 15:47:59.216|Dbg|0001| Phone System disconnected
2022/05/24 15:47:59.216|Dbg|0001| Finish updating certificates. Updated 0 certificates
In the past we could use /usr/lib/3cxpbx/PbxConfigTool -renew-certificates but this is going back a few years.
I can ping activate.3cx.com, but i dont think it has tried to renew since the latest updates were applied.