Solved Provisioning not working, but cfg-file download works

Status
Not open for further replies.

ssstofff

Forum User
Joined
Aug 19, 2020
Messages
10
Reaction score
0
I'm struggling with a Yealink T57W provisioning (fw 97.84.0.35 installed from here https://www.3cx.com/sip-phones/yealink-t5-series/)

It works from server A, not from server B.
Both servers have identical version: 16.0.7.930
Server A is Standard version (3cx fqdn)
Server B is Professional (custom fqdn)

Initiating on phone the prov from server A works. The red led starts to blink, reboots and done.
Initiating on same phone the prov from server B does nothing. No red led blinking.
However I can download the cfg-file from server B like: https://xxxxxxxxxx/provisioning/p2eze07u6h88x8/805ec0ae1c04.cfg
When I upload this file on the phone ... red led starts to blink, reboot and .... provisioned.

By testing between both servers, I did replaced the MAC address in the provisioning extension profile.

Server B
  • 3CX Version: Professional 16.0.7.930
  • Server OS: Debian 9
  • Is the 3CX Server Hosted and where: AWS EC2
  • IP Phone Make/Model/Firmware: T57W, fw 97.84.0.35
  • Provisioning Method: STUN
  • Trunk Provider or Gateway Make/Model: Twilio
  • Has the Firewall Checker passed: YES
  • Are custom Phone Templates being used: NO
Any hint?
 
Last edited:
SERVER A is also cloud hosted and phone used in STUN mode ?
 
Most likely the certificate is the issue. To test this on the security settings on the phone you can disable the setting "only accept trusted certificates"

1604615274029.png1604615274029.png
 
  • Like
Reactions: ssstofff
I'm struggling with a Yealink T57W provisioning (fw 97.84.0.35 installed from here https://www.3cx.com/sip-phones/yealink-t5-series/)

It works from server A, not from server B.
Both servers have identical version: 16.0.7.930
Server A is Standard version (3cx fqdn)
Server B is Professional (custom fqdn)

Initiating on phone the prov from server A works. The red led starts to blink, reboots and done.
Initiating on same phone the prov from server B does nothing. No red led blinking.
However I can download the cfg-file from server B like: https://xxxxxxxxxx/provisioning/p2eze07u6h88x8/805ec0ae1c04.cfg
When I upload this file on the phone ... red led starts to blink, reboot and .... provisioned.

By testing between both servers, I did replaced the MAC address in the provisioning extension profile.

Server B
  • 3CX Version: Professional 16.0.7.930
  • Server OS: Debian 9
  • Is the 3CX Server Hosted and where: AWS EC2
  • IP Phone Make/Model/Firmware: T57W, fw 97.84.0.35
  • Provisioning Method: STUN
  • Trunk Provider or Gateway Make/Model: Twilio
  • Has the Firewall Checker passed: YES
  • Are custom Phone Templates being used: NO
Any hint?
Can you run a syslog on the Yealink device and see what it picks up, if you increase the logging level to 6 you should see the error when it tries to download the config?

Does it work if you enter the provisioning link into the GUI and click auto provison now?

http://support.yealink.com/faq/faqInfo?id=712
 
It's indeed the 'Only Accept Trusted Certificates'. When turned off, it picks up the provisioning.

So the diff between Server A and B is that server A is with a 3CX FQDN and seems to be a 'Trusted Certifcate' the SSL.

How to have for server B the custom FQDN SSL having 'trusted'? Because the purpose of provisioning is provisioning ... which is now blocked by the phone default settings.

After provisioning, the 'Only Accept Trusted Certificates' is turned on again. Next updates from the 3CX server are unreachable again for the phones.
 
Last edited:
It's indeed the 'Only Accept Trusted Certificates'. When turned off, it picks up the provisioning.

So the diff between Server A and B is that server A is with a 3CX FQDN and seems to be a 'Trusted Certifcate' the SSL.

How to have for server B the custom FQDN SSL having 'trusted'? Because the purpose of provisioning is provisioning ... which is now blocked by the phone default settings.

After provisioning, the 'Only Accept Trusted Certificates' is turned on again. Next updates from the 3CX server are unreachable again for the phones.
Yealink have a list of certificates they trust:
http://support.yealink.com/faq/faqInfo?id=691
 
It's indeed the 'Only Accept Trusted Certificates'. When turned off, it picks up the provisioning.

So the diff between Server A and B is that server A is with a 3CX FQDN and seems to be a 'Trusted Certifcate' the SSL.

How to have for server B the custom FQDN SSL having 'trusted'? Because the purpose of provisioning is provisioning ... which is now blocked by the phone default settings.

After provisioning, the 'Only Accept Trusted Certificates' is turned on again. Next updates from the 3CX server are unreachable again for the phones.


your options are
Use a 3cxFQDN as their certificates seem to be trusted by yealinks

Try Importing your certificate into the trusted certs on the phones

or create a custom template that switches off the "only accept trusted certificates" setting.
 
OR change the provider of your custom FQDN to one that has supported baked into the firmware.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet