Solved PEM Chain Format

Status
Not open for further replies.

DavePrimisys

Bronze Partner
Advanced Certified
Joined
Aug 29, 2020
Messages
3
Reaction score
1
I converted my PFX cert/key into 2 PEM files, like this but I get an error in the log stating that the PEM chain cannot be loaded.

openssl pkcs12 -in SBC.pfx -out SBC-nokeys-out.pem -nodes -nokeys

openssl pkcs12 -in SBC.pfx -out SBC-withkeys-out.pem -nodes

Is there a specific command/format I need with my PEM files to get the correct format with the chain files included? I manually added the chain file additions to the bottom of the certificate pem file, but it still fails to load them properly.

08/07/2021 12:35:31 AM - TLS transport for Teams is not available. Teams integration is disabled
08/07/2021 12:35:31 AM - Failed to create Teams transport
08/07/2021 12:35:31 AM - Exception creating Teams transport: Failed opening PEM chain file
08/07/2021 12:35:31 AM - Failed to load certificate: domain_cert_SBC.pem
08/07/2021 12:35:31 AM - Failed to load certificate: domain_key_SBC.pem
 
Hi @DavePrimisys

Each certificate in the chain must begin with a "-----BEGIN CERTIFICATE-----" and end with an "-----END CERTIFICATE-----". Also make sure that there are no spaces and that the formatting is correct.

You can verify each certificate in the chain using this link.
 
Is the private key .pem file supposed to start with -----BEGIN RSA PRIVATE KEY----- or -----BEGIN PRIVATE KEY-----?
 
-----BEGIN RSA PRIVATE KEY-----
It also cannot require a decryption key

I wrote a guide here:
https://www.3cx.com/community/threads/update-renew-certificate.77468/post-356117
Great write up. I ended up having to edit the root_cert_teamsdirectrouting.pem file location in the /var/lib/3cxpbx/Instance1/Bin/Cert/ folder to manually include the SSL.com intermediate cert chain, and removed it from the origional certificate pem file. Things are happy now. Thanks for the point in the right direction!
 
  • Like
Reactions: YiannisH_3CX
Glad to see you got things working
 
Status
Not open for further replies.