On-Premise: Certificate renewal and the new TLS certificate lifetimes

Ecki

Customer
Joined
Jun 7, 2022
Messages
16
Reaction score
3
Hello,

the CA/Browser Forum has officially set the schedule for shorthening the lifetime of TLS certificates:
  • From today until March 15, 2026, the maximum lifetime for a TLS certificate is 398 days.
  • As of March 15, 2026, the maximum lifetime for a TLS certificate will be 200 days.
  • As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days.
  • As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days.
Source: https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days

We understand this does not impact the 3CX systems managed/hosted by 3CX and a 3CX FQDN very much.

But what about 3CX on-premise with a non-3cx fqdn? Is there an offical (supported) way of doing this?

With a lifetime of >=398 day doing this manually was ok, 100/47 days not so much.
https://www.3cx.de/forum/threads/wildcard-zertifikat-erneuern.97519/#post-316436

Is it supported to use certbot to update the nginx certificate and xapi to update the secure sip certificate/key?

- certbot is available via the 3cx repository
- xapi / configuration api:
Code:
PATCH {{baseUrl}} /SecureSipSettings

    {
      "Certificate": "<string>",
      "PrivateKey": "<string>"
    }

Is there anything on the roadmap to make this easier manageable via the admin interface?

Thanks in advance
Ecki
 
Is it that important that you have your own FQDN and SSL certificate in use? With the 3CX certificates everything is automated.

It would be difficult to automate the use of your own FQDN and SSL certificate.

so you need to weigh the cost of your time vs your convenience.

Customers most of the time do not even see their FQDN, especially is using IP Phones and the PWA.
 
Currently our own FQDN is a business requirement (i.e. to produce customer friendly URLs for web meetings) and therefore important to us.

So it's supported to use a custom FQDN but there is no further support or documentation planned to
support the challenges coming with that?
 
Tbf the 47-day renewal interval is 4 years away. Though the "pain point" is high enough we're already thinking about it for our few remaining paid certs...one is a wildcard we use throughout our hosting infrastructure. :(
 
  • Like
Reactions: Evolute IT

Latest Posts

Forum statistics

Threads
111,963
Messages
589,998
Members
164,868
Latest member
swegner