Solved Renewal Public Certificate SSL

Status
Not open for further replies.

fred-davila

Premier Customer
Joined
Nov 3, 2011
Messages
1
Reaction score
0
Hello All,

I'm trying to update my public cert that expired on Jan 5th of 2020 but I can't access the page; https://www.3cx.com/docs/self-hosted-instances-ssh/
And don't remember the process to update and all I found in the forum didn't work.

Any help? also why the link is not working anymore on 3cx website?

I remember we have a tool we could use to generate the CSR that have the private key and then rename the file but don't remember the name and process for it.
I have a windows version.

Thanks
Fred
 
Hi Fred!

The general instruction are outlined here:
https://www.3cx.com/community/threads/ssl-certificate-renewal.64920/

Basically you just replace the "old" cert files with the new ones.
A few things where you can go wrong:
- The file must be in unencrypted PEM format. Some CAs might give them to you in other formats, but you need to convert them. Just check the format of the current "old" files and compare to the "new" ones
- If Linux, make sure when you copy the new files, you give them the correct file rights!
- Don't forget any Intermediate Certificates!

After you replace the files you need to restart nginx.

I do have to point out though that if you are having difficulties, maybe you should consider re-installing 3CX using the 3CX certificates?
Certificates are renewed automatically, by 3CX as long as valid maintenance exists.
 
Dear NickD,
The link you provided is broken. I also need instructions how to replace public certificate. I remember it was here, on 3CX forums, but now all links are broken and point to different topics.
 
I found locations of certificates, finally:
Windows: “C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1”
Linux: “/var/lib/3cxpbx/Bin/nginx/conf/Instance1”

You can edit path to your certificates in /var/lib/3cxpbx/Bin/nginx/conf/Instance1/nginx.conf if new ones has different names or you want put then somewhere else
 
You can edit path to your certificates in /var/lib/3cxpbx/Bin/nginx/conf/Instance1/nginx.conf if new ones has different names or you want put then somewhere else
A word of caution, when you upgrade your PBX, any changes to this file will be reverted. I highly suggested, if you have decided to go down this route, do use the default path and filenames.

Just my 2 cents.
 
To confirm, does the below still work, nothing has changed with 3CX? The below process worked recently at 3 of our sites with expired certificates (all Windows 2016 servers running 3CX ver 16.0.1078) but last night this failed, the Nginx service would not shutdown in a timely manner, it would hang and from experience I know Nginx will hang if the "pem" files are not named correctly but that wasn't my issue so I'm thinking either the below process has changed, or maybe the .crt file I received is off/bad.

I too looked as some past links, such as this from a thread I posted https://www.3cx.com/docs/renewing-ssl-certificate and can no longer find the below instructions, in fact this link Installing an SSL Certificate for a Custom FQDN in 3CX PBX contains something totally different. I'm confused.

We use CSRgenerator.com which will create a file containing the information I submit to our Security team who then purchases a certificate. Within the information created by CSRgenerator.com is the "key", the text from ----BEGIN PRIVATE KEY---- to ----END PRIVATE KEY is placed into the domainName-key.pem

The certificate we recevie from DigitCert is then renamed (domainName-crt.pem) and this file along with the above is placed into the default folder C:\Program Files\3CX Phone System\Bin\nginx\conf\instance1. The Nginx service is restarted, all is good.
 
Solve my issue, it was the certificate itself. The above steps worked. Our security team generated a new certificate, some sort of options they can select that pertain to if it is IIS, Windows, Linux, and they selected "nginx"
 
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet