Secure SIP on Trunk - 503 Certificate Validation Failure

Status
Not open for further replies.

Dutchman

Customer
Basic Certified
Joined
Nov 19, 2019
Messages
5
Reaction score
0
After configuring TLS on a sip trunk (which is supported by our provider) the 3CX reports that the certificate is invalid.

01/29/2020 5:55:26 PM - [CM504005]: Registration failed for: Lc:10000(@TrunkName[<sip:[email protected]:5060/TLS>]); Cause: Cause: 503 Certificate Validation Failure/REGISTER from local

From this log i cant really see if its the PBX's certificate failure or the certificate of the cloud PBX on which im trying to connect to.

on using "openssl s_client -showcerts -connect sbc.sc.voipit.nl:5081" i can see that the certificate is validated by digicert and it seems to be verified.
Verify return code: 0 (ok)

I've also inserted the root CA of digicert rapidssl which seems to be valid til 2027

Does anyone experience the same problem? or know where i can look?
 
I have the same problem and can't get it to work. On Provider side there is a Letsencrypt which is also valid and 3CX-PBX keeps telling me Cause: Cause: 503 Certificate Validation Failure/REGISTER from local

I am on contact with 3CX Support .. i hope they find the problem!
 
I have the same problem and can't get it to work. On Provider side there is a Letsencrypt which is also valid and 3CX-PBX keeps telling me Cause: Cause: 503 Certificate Validation Failure/REGISTER from local

I am on contact with 3CX Support .. i hope they find the problem!
Do you have any update on this? i'd like to get this trunk to work on TLS
 
5060/TLS ... that cannot go together
 
are we talking about wildcard certs?

*.provider.com

instead of

sip.provider.com
 
5060/TLS should go together, but thats not the part that i've configured.
Im using an outbound proxy on port 5081 with TLS.

I dont know what kind of certs we're talking about because the 3CX PBX gives me a very obscure log.
 
1582118419018.png

The certificate you manually loaded here. Is it a wildcard certificate?

Or did you not load this certificate?
 
I tried both, i got a certificate from our supplier which i uploaded. and i tried to remove the certificate.
Do you know how i can check if its a wildcard or not? and does it really matter?
 
Yes, wildcard certs are not supported.

Was the file delivered you as a .pem file?
 
What is your cert you been given?
It should be this one, which needs to be uploaded into the place shown by John
1582118904454.png

It is not a WildCard, but yes it would matter as SIP cannot work on WildCard certs as per RFC.
 
  • Like
Reactions: Dutchman
Wauw thanks for the information.
Im gonna check with my supplier as they have just started with TLS.

No the certifacte wasnt delivered as PEM sadly.

is the upload of the TLS certificate required for operation or is it only for validation?
 
it is needed as our sip server does not carry any roots itself and therefore must be added in context to the "line" for performance reasons. PEM and CRT is an interchangeable file format ending.
 
Status
Not open for further replies.

Forum statistics

Threads
111,938
Messages
589,836
Members
164,821
Latest member
M_R