Solved nginx failed to start after upgrade to v18 and Debian 10

Status
Not open for further replies.

msardi

Free User
Joined
May 24, 2016
Messages
19
Reaction score
1
Hi all,
After upgrade to v18 and Debian 10, nginx is not stating. When I check service status I get this error.

abr 21 11:48:17 3cx nginx[495]: nginx: [emerg] SSL_CTX_use_certificate("/var/lib/3cxpbx/Bin/nginx/conf/Instance1/xxxxxxxx-crt.pem") failed (SSL: error:140AB18F:SSL routines:SSL_CTX_use_certificate:ee key too small)
abr 21 11:48:17 3cx nginx[495]: nginx: configuration file /etc/nginx/nginx.conf test failed

Any idea?

Thanks!

Matías
 
Are you using a 3cx ssl certificate or your own ssl certificate ?
 
Can you provide a bit more info about the situation/setup?

• How exactly did you upgrade this machine, was it via the Upgrade button that appears in the 3CX Management Console or did you deploy a Debian 10 machine?

• How was this machine deployed to start with? Was it via our deployment wizard (PBX Express), 3CX ISO, marketplace or manual installation?

• Are you sure it's only the nginx sesrvice that's not running? SSH to the machine, run the following and provide us with the output:
systemctl list-units 3CX* postgre* nginx*
 
I did the upgrade via the upgrade button in the Management Console, after that I loose conection in the phones and the Management Console stop working.
It is a virtual machine, if I am not wrong I have installed with debian-amd64-netinst-3cx.iso
This is the output of the command:

-----------------------------------
root@3cx:~# systemctl list-units 3CX* postgre* nginx*
UNIT LOAD ACTIVE SUB DESCRIPTION

● nginx.service loaded failed failed A high performance web server
and a reverse proxy server
postgresql.service loaded active exited PostgreSQL RDBMS
[email protected] loaded active running PostgreSQL Cluster 11-main
[email protected] loaded active running PostgreSQL Cluster 9.6-main

LOAD = Reflects whether the unit definition was properly loaded.
ACTIVE = The high-level unit activation state, i.e. generalization of SUB.
SUB = The low-level unit activation state, values depend on unit type.

4 loaded units listed. Pass --all to see loaded but inactive units, too.
To show all installed unit files use 'systemctl list-unit-files'.
----------------------------------------

I looked for this nginx error and found that the problem is SSL certificate is less than 2048 bits. As I am in a vm, I reverted to the last snapshot and got the 3xc running in v16 again, so I renewed certificates with this procedure.



But I have the same problem.
 
Last edited by a moderator:
Hi,

You are using a custom FQDN so there is no 3CX generated certificate. The reason it fails, as you correctly said is because the key size is less than 2048 bits. You need to manually replace your current certificate with a new one (which should be >= 2048 bits) and then perform the O.S upgrade.
 
I configured a new 2048 bits ssl certificate, then did the upgrade and it worked correctly, now pbx is up and running v18 and Debian 10.

Thanks for all!

Matías
 
Great, glad you got it sorted. I’ll go ahead and mark this now as solved.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet