Password lost on upgrade from v18 to v20

Status
Not open for further replies.

MatsW

Free User
Joined
Mar 10, 2009
Messages
76
Reaction score
0
I had a Windows based v18, but because of upgrade limitations I had to create a Debian host. Creating and configuring the v18 works fine. I can log in on port 5001 with https and certificate works.
But if I upgrade to v20 then my credentials are someway lost because then login to 5001 no longer works.

What is worse is that I've had to try rebuilding my Debian system a number of times while trying to figure out what the heck is going on. But now the last time I got this error message a the end of the Debian installation
Certificate Authority Error: ID (429) - too many certificate requests for the same FQDN. This means you have tried to generate a certificate for this FQDN more than 5 times in the last 7 days. If you want this certificate you need to wait until the counter is adjusted. If you cannot wait, you will need to choose another FQDN. To re-install 3CX using the same license key with a different FQDN you need to release your current FQDN to free your license. Follow this guide: https://www.3cx.com/docs/fqdn-management-allocation/
What is even worse is that https://www.3cx.com/docs/fqdn-management-allocation/ leads to a "404 Error" page. So now I'm really stuck in the mud :-(
 
V20 uses the system owner extension or email, not the admin user.
 
  • Like
Reactions: OlegR_3CX
Indeed, no more Super admin user, and only user who have a system owner right, this is a new way and Admin console will be found in your Webclient from now on.
 
Well, in that case how come that the upgrade doesn't allow you to set the password of the user who have a system owner right? Since if it hasn't been set then system becomes inaccessible?
The odd thing is that if I click Back in some screen when I logged in to port 5015, then a screen "License key" followed by "Create a 3CX root account" appears between "Configure your 3CX Install" and "We detected your Public IP Address as ..."
So what is this "3CX root account"? One thing for sure is that those credentials doesn't work
 
You can reset the SO password on the login screen as long as it has a unique email address.

The screen you mention sounds like a bug tbh.
 
Well, that's the problem that v20 seems to have problem to send mails to my mail server. I was just about to change email address to a gmail address when the freaking certificate limit hit me.
 
Ok. So now the certificate timeout has expired so I have create a new v18 Debian and restored config from my Win-10 box.
Certificates work, management console at port 5001 work. But when I try to access webclient at https://xxx.3cx.se:5001/webclient then I get the login screen, type in the extension number of the system owner and the password for system owner and press Login. But all that happens is that login screen reappears. No error message. Nothing. No reason to try to upgrade to V20 as long as webclient doesn't work.
I've tried with Edge, Firefox, Crome with incognito windows on all but always the same result. What could be wrong? How do I debug this? Are there any logs in Debian to look at?
 
I have decoded the HTTPS traffic between the client and Debian machine, and there the following can be seen (xx.xx.xx.xx is my public ip)

Code:
1365    22:46:21,238061    192.168.100.59    64536    xx.xx.xx.xx    5001    HTTP2    602    HEADERS[15]: POST /webclient/api/MyPhone/session
1366    22:46:21,238119    192.168.100.59    64536    xx.xx.xx.xx    5001    HTTP2/JSON    149    DATA[15], JSON (application/json)
1369    22:46:21,239003    xx.xx.xx.xx    5001    192.168.100.59    64536    TCP    60    5001 → 64536 [ACK] Seq=21756 Ack=4448 Win=64128 Len=0
1370    22:46:21,239051    xx.xx.xx.xx    5001    192.168.100.59    64536    HTTP2    96    WINDOW_UPDATE[15]
1371    22:46:21,241895    xx.xx.xx.xx    5001    192.168.100.59    64536    HTTP2    195    HEADERS[15]: 403 Forbidden, DATA[15]
1372    22:46:21,242031    192.168.100.59    64536    xx.xx.xx.xx    5001    TCP    54    64536 → 5001 [ACK] Seq=4448 Ack=21939 Win=1049600 Len=0

Any idea why access to /webclient/api/MyPhone/session should be forbidden?
 
Problem solved. It turns out that there is a default setting that will block webclient access. But whats worse, it's located in a location that is NOT obvious for a person skilled in the art to find.
In the extension assigned as System Owner, select Phone Provisioning tab, then in Your phones drop down list select 3CX App.
This will open up a different content of the tab where there is a checkbox under Access called Block Access to 3CX Apps / Web Client.
It is by default enabled which means that a fresh install of v18 can't be upgraded to v20 unless you find this setting and unselect it.
And one can really ask what has webclient access todo with 3CX App client access? These are two separate setting where it's crusial that the first is NOT enabled. Otherwise you're locked out from your server forever once upgraded to v20.
3CX really need to update instructions asap
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,951
Messages
589,886
Members
164,843
Latest member
sambannoura