Manual SSL Renewal - Possible?

Status
Not open for further replies.

TitleRequired

Bronze Partner
Advanced Certified
Joined
Mar 18, 2020
Messages
55
Reaction score
10
Have a system running v18 - just updated to 18.03. Debian 10.

It started alerting a week or so back that SSL renewal had failed (3cx.co.uk address)

Only just got approval to look at it today.

Have installed the available updates, and debian updates. Rebooted.

Is there a way to run a manual SSL renewal?

Error in log is:
SL Certificate renewal has been failed. Error: SSL certificate failed due to network conditions. Unable to reach Certificate Issuing Servers. We�ll try again in a couple of hours.

From PBXConfigToolRenewCertificates.Log

2022/05/24 15:47:58.836|Dbg|0001| Connecting to PhoneSystem
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected = True (waittime=00:00:00.3353070)
2022/05/24 15:47:59.172|Dbg|0001| PhoneSystemConnected(2) = True
2022/05/24 15:47:59.174|Dbg|0001| Parameter name: REGENERATE_CERTIFICATE_EXPIRED_IN_DAYS, value = 25
2022/05/24 15:47:59.174|Dbg|0001| Is temporary certificate generated = False
2022/05/24 15:47:59.174|Dbg|0001| regenerateFromStr = , regenerateToStr =
2022/05/24 15:47:59.174|Dbg|0001| SIPPORT port in PBX = 5060
2022/05/24 15:47:59.174|Dbg|0001| Using SipPort = 5060
2022/05/24 15:47:59.174|Dbg|0001| ENABLE_DNS_HELPER =
2022/05/24 15:47:59.174|Dbg|0001| TNL_CLIENT_LISTEN_PORT port in PBX = 5090
2022/05/24 15:47:59.174|Dbg|0001| Using TunnelPort = 5090
2022/05/24 15:47:59.213|Dbg|0001| Processing directory = /var/lib/3cxpbx/Bin/nginx/conf/Instance1, regenerateCertificateExiredInDays = 25, temporaryCertificateGenerated = False, regenerateNotSelfSignedCertificatesFrom = 0, regenerateNotSelfSignedCertificatesTo = 7, isPassiveFailoverMode = False, enableDnsHelper = False
2022/05/24 15:47:59.213|Dbg|0001| Real (not self-signed) certificates regenerates from 0 to 7 hour. Skip.
2022/05/24 15:47:59.213|Dbg|0001| Processing directory /var/lib/3cxpbx/Bin/nginx/conf/Instance1 completed
2022/05/24 15:47:59.213|Dbg|0001| Disconnecting from PhoneSystem
2022/05/24 15:47:59.216|Dbg|0001| Phone System disconnected
2022/05/24 15:47:59.216|Dbg|0001| Finish updating certificates. Updated 0 certificates

In the past we could use /usr/lib/3cxpbx/PbxConfigTool -renew-certificates but this is going back a few years.

I can ping activate.3cx.com, but i dont think it has tried to renew since the latest updates were applied.
 
There's really no need. It doesn't sound like your certificate has expired yet so there's no rush. You only risk hitting the LE attempt limit and then ensuring you can't renew for another week. You don't mention what version of 3CX you were on prior to updates, but it's likely the updates resolved whatever was preventing the renewal.

Also, I noticed you said you performed Debian updates. There should be no OS level updates done outside of what 3CX does with automatic updates. It puts you in unsupported territory. At this point the supported environment is install from 3CX ISO, leave 3CX on automatic updates which takes care of the OS, and hope they test it very well!
 
Yes, it has expired.

I think it was 18.01 but I didn't make a note before hand. It was v18 though (rather than v16)

Happy to wait overnight and see if it renews on its own, just frustrating.

Edit- It was v18.0.1.237 - certificate expired on the 11th.
 
Last edited:
Certificate renewed overnight. Still would like to know if it can be done manually!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru