3CX - This is very frustrating.
Here is what I've found
Yealink phones by default have "security.trust_certificate" set to true. This means that if a certificate is not signed by a trusted CA, the phone will not accept any provisioning files from an https connection. Yealink does not include any trusted CAs and so provisioning files referenced by https urls will never work. - and all 3CX ver 15 provisioning files are https
Either:
1) manually modify the security.trust_certificate parameter found on the Security / Trusted Certificates tab as "Only Accept Trusted Certificates" to Disabled / False so it will accept https urls or
2) modify the NGINX webserver settings to allow for non https connections and ensure the provisioning urls are http or
3) possibly manually upgrade the phone firmware to the latest version which may trust the new CA used by 3CX.
Either way, more planning should be included on this before its released.
And just for the record - 3CX has a world class sales team, marketing team, executive and dev team that do a lot of amazing things. There are some very impressive people at 3cx. These last three 12,14 and now 15 are released too early - please replace your product management team.