Solved Registration failed Cause: Cause: 503 Certificate Validation Failure/REGISTER from local

Status
Not open for further replies.

jener

Silver Partner
Basic Certified
Joined
Jul 20, 2022
Messages
29
Reaction score
3
Hi Folks,

Im busy to setup a demo PBX wich connects through a SIP-Trunk that requires TLS for SIP and SRTP for audio. In 3CX I need to upload the Root Certificate for this SIP-Trunk.
When I enable the trunk i get the message:

Code:
Registration failed for: Lc:10000(@RoutIT[<sip:[email protected]:0/TLS>]); Cause: Cause: 503 Certificate Validation Failure/REGISTER from local

Okay, now im diving into the TLS headers to find out what certificate is used by the Trunk:

Code:
openssl s_client -showcerts -debug -connect sbc.sc.voipit.nl:5081  -bugs

This tells me this:
Code:
issuer=C = US, O = DigiCert Inc, CN = RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1
According to DigiCert this is the corresponding root certificate: https://cacerts.digicert.com/RapidSSLTLSDVRSAMixedSHA2562020CA-1.crt.pem

When uploading this root certificate the error keeps coming back and the trunk isnt registering. Any idea how to deebug further to get the trunk registered?

im using 3CX 18 update 4 (build 965)
 
Check the TLS handshake and make sure that the server is advertising the correct name that matches the certificate. Also make sure that its not missing any intermediate certificates from the chain.
Also check this: https://www.3cx.com/docs/sip-trunk-tls-srtp/
 
  • Like
Reactions: Charles_3CX
Check the TLS handshake and make sure that the server is advertising the correct name that matches the certificate. Also make sure that its not missing any intermediate certificates from the chain.
Also check this: https://www.3cx.com/docs/sip-trunk-tls-srtp/

Hi YiannisH,

  1. I've checked the advertising name of the sip trunk: Server certificate subject=CN = sbc.sc.voipit.nl
  2. I've added both the Intermediate certificate RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1 and the root certificate DigiCert Global Root CA to the pem file
  3. I still get Cause: Cause: 503 Certificate Validation Failure/REGISTER from local error when trying to register

To be sure i've added the certificate file in text format. This is the exact file im uploading to the 3CX server for this sip trunk, maybe you can see if there something wrong with the file?

Best regards,

Erik
 

Attachments

The file looks OK but unfortunately there is not a lot more I can see from my side. You will need to troubleshoot this one on your own or with the help of your provider.
 
  • Like
Reactions: jener
The file looks OK but unfortunately there is not a lot more I can see from my side. You will need to troubleshoot this one on your own or with the help of your provider.

a little update on this one (for the community). the SIP-Trunk / SBC in this case was using a too short Diffie/Helman key (1024 bit instead of 2048 or higher) therefore 3CX server didn't accept the certificate (wich was okay).

Disabling "PCI compliance SSL/SecureSIP Transport and Ciphers" under Security / Anti-Hacking did the trick.
 
  • Like
Reactions: YiannisH_3CX
Glad to see you were able to figure this out
 
  • Like
Reactions: jener
Status
Not open for further replies.

Forum statistics

Threads
111,991
Messages
590,166
Members
164,929
Latest member
Cloudstar