Security Certificate Expired

Status
Not open for further replies.

Thiek

Premier Customer
Joined
Dec 5, 2017
Messages
134
Reaction score
27
I'm running 3CX version 16.0.493 on a Win2012 R2 server, we installed our own cert using CSR Generator but it has expired and we have many more about to expire. When I log into the admin web portal using the FQDN I get an error that won't allow access NET::ERR_CERT_DATE_INVALID

I'm looking at a couple different threads on how to update a cert but nothing is working. This thread https://www.3cx.com/docs/secure-sip/ talks about updating the "certificate" and "private key" information under Settings>Security>Secure SIP which then updates the two files domain_cert_domainname.com.pem and domain_key_domain-name.com.pem in the C:\ProgramData\3CX\Instance1\Bin\Cert folder. However, I'm then looking at this thread https://www.3cx.com/docs/renewing-ssl-certificate which talks about replacing the contents within the "key" and "cert" files and restarting the Nginx service but just like this guy https://www.3cx.com/community/threads/ssl-certificate-renewal.64920/ the service crashes.

Anyone figure out what the correct solution is? Also, what do I do with the .com.crt file, the certificate, do I need to run the install wizard and if so what "store" do I place it under?
 
Ahh the joys of custom FQDN.. still not sure why people bother..


Not sure why you are talking about the certificate store since that's not mentioned anywhere in that guide.
 
  • Sad
Reactions: TonyBindra
Thank you everyone, I see what I did wrong and within a few minutes all is working. I was following the instructions under Settings > Security > Secure SIP tab "To use Secure SIP you need to create a key and certificate for each network interface. Click here for more information" which threw me off. I'll explain in case someone else makes the same mistake. I knew something was off last Friday because I was not doing anything with the actual certificate like I would on a new build of 3CX. Probably focused on starting the weekend and opening a cold one :rolleyes:

Using CSRgenerator.com this will created a file that contains the information we submit to get a certificate created. This information generated contains the "key", the text from ----BEGIN PRIVATE KEY---- to ----END PRIVATE KEY which goes into the xyz-key.pem file.

Also, this information generated from CSRgenerator.com contains ----BEGIN CERT REQUEST--- to ---END CERT REQUEST and I was placing this in the xyz-crt.pem file which is totally wrong. The xyz-crt.pem is the actual .crt you would get from someone like GoDaddy, NetworkSolutions, or DigitCert. All I needed to do was rename the actual certificate.crt file using the naming format outlined in the 3CX SSL link and now all is good.

Oh, and yes to Complex1, we are using version 16.0.493 on a Win2012 R2 because to me the new e911 features rank much higher than APN which we don't use, and is why Win2016 is needed.
 
  • Like
Reactions: JohnS_3CX
Hi @Thiek

Move to a supported OS and upgrade your 3CX system for compatibility, security and future-proofing.

If you are comfortable with Debian it is a more cost effective option and also uses less resources.

Just some food for thought, as going forward your current OS is neither supported not being tested in our product's quality assurance.
 
Thanks JohnS, that's our plan to get to Win2016 but with 12 sites on a virtual host running Win2012, all sites 24x7 365, it takes a bit of planning for someone to travel to the site and build the new host and then I can upgrade. Obviously I missed the many email notifications from 3CX warning about the end of life Win2012, or maybe I'm not even receiving such notifications?
 
Yes, it's understandable it takes some planning and of course testing from beforehand before you re-deploy.

Sorry you missed it :( in the past months we made an effort to inform all partners and customers about the upcoming changes:

01/2020 - The Blog Post informing about the upcoming changes
https://www.3cx.com/blog/releases/apple-push-update-windows/

03/20 - You or your assigned 3CX Partner was informed ahead of time.

04/2020 - The Blog Post for update 5
https://www.3cx.com/blog/releases/remote-working-video-app/

05/2020 - Email sent to end users to try and get them to upgrade to U5 (which needs a newer Windows OS)

Check whether anything ended up as spam, or whether the notifications are going to an account email that you are not monitoring currently, so you can always stay in the loop!
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur