[Request/Suggestion] Adjust D-Telekom CompanyFlex Trunk Template

Status
Not open for further replies.

Gasha

Titanium Partner
Basic Certified
Joined
Jul 16, 2021
Messages
59
Reaction score
63
Good morning,

many of our customers are using a 3CX PBX hosted on our root server.
Our servers are using a redundant internet connection system, therefore we cant register the above named trunk.

Your whitepaper for this trunk says that it’s currently not working due to the TLS certificate problem.
„TLS currently does not work as 3CX and Deutsche Telekom TLS implementations are not compatible. This means that anyone that is not on a Deutsche Telekom internet connection cannot use the CompanyFlex trunks because in this case, TLS is required as the transport protocol.“

All of our customers are Telekom customers, we cant change every SIP trunk to a different provider.
Therefore we request a change in the template, which includes the root certificate from Telekom or maybe a different way to register the new company flex trunks while using another internet connection rather than Deutsche Telekom.

We would appreciate it if someone official could and would chime in on this matter. Please keep us informed and updated, many thanks!
 
Good morning,

many of our customers are using a 3CX PBX hosted on our root server.
Our servers are using a redundant internet connection system, therefore we cant register the above named trunk.

Your whitepaper for this trunk says that it’s currently not working due to the TLS certificate problem.
„TLS currently does not work as 3CX and Deutsche Telekom TLS implementations are not compatible. This means that anyone that is not on a Deutsche Telekom internet connection cannot use the CompanyFlex trunks because in this case, TLS is required as the transport protocol.“

All of our customers are Telekom customers, we cant change every SIP trunk to a different provider.
Therefore we request a change in the template, which includes the root certificate from Telekom or maybe a different way to register the new company flex trunks while using another internet connection rather than Deutsche Telekom.

We would appreciate it if someone official could and would chime in on this matter. Please keep us informed and updated, many thanks!
Hi!

The problem is not the root certificate, it is the actual implementation of SIP TLS DT requires.

That, along with the fact that when a CompanyFlex account is being registered from a different Internet connaction other than a DT one, is is required to be SIP TLS, has made us put that limitation in place.

For the time being there is nothing we can do, and seeing that DT is the only provider we have worked with that requires this specific SIP TLS implementation, it is not in our immediate plans to implement this.

I should note though that in DT internet connections, there should be no problem operating it.
 
Hi!

The problem is not the root certificate, it is the actual implementation of SIP TLS DT requires.

That, along with the fact that when a CompanyFlex account is being registered from a different Internet connaction other than a DT one, is is required to be SIP TLS, has made us put that limitation in place.

For the time being there is nothing we can do, and seeing that DT is the only provider we have worked with that requires this specific SIP TLS implementation, it is not in our immediate plans to implement this.

I should note though that in DT internet connections, there should be no problem operating it.
Hi,

thanks for your reply.
As we tested on different system on the same root server, we are able to register the trunks via TLS.
I mentioned the certificate, because the global root certificate is installed on the other pbx.

(https://corporate-pki.telekom.de/downloads.html)

As far as I know we need to implement the certificate as *.pem file on the 3cx pbx.
Are there any ways that you request the certificate from Telekom in this format?


We cannot change the *.pfx without loosing the global trust chain.
I guess, that’s the only way we can archieve a solution.

Thanks for your patience and answer so far.
 
You can convert the PFX file to PEM and then in the PEM, just add all the intermediate certificates that are required as well.

As I explained though, the problem is the implementation and there will be some aspects not working and/or not supported neither by us and DT for CompanyFlex and this has been confirmed during our communication wit DT.

The specifications are here: https://www.telekom.de/hilfe/downloads/1tr119-2021.pdf
 
Status
Not open for further replies.

Forum statistics

Threads
111,992
Messages
590,171
Members
164,931
Latest member
admintest