Security certificates do not work after installing update 7

Thiek

Premier Customer
Joined
Dec 5, 2017
Messages
134
Reaction score
27
I installed update 7 about 2 or 3 weeks back, and then today I updated the security certificate as it was about to expire. Did the standard routine of placing the 2 .pem files in the …ProgramData\3CX\Bin\nginx\conf\Instance1 folder and restarting the Nginx service. However, the cert did not update. Restart Nginx again, rebooted, refreshed my license key… no luck. Noticed in the Activity Log it said something about the folder …Program Files\3CX Phone System\Bin\nginx\conf\instance1 which is where the certs used to be stored on v18. I looked in this folder and to my surprise a copy of the old .pem files were shown here. I placed the new in this folder, restarted Nginx but nothing happened. I then restored a snapshot back to pre-update 5, 6, and 7 and I was able to successfully install my certificates.

This this procedure change? I know 3CX sent out a warning saying get your system to update 6 otherwise Security Certs will fail!
 
The 3CX warning, yes that I get but something changed with Update 7. I updated 4 security certs, 3 were on production systems that were patched with updates 5 and 6, and the 4th was a development box running update 7. The 3 productions system updated with no issues as I do this all the time, but the development box did now work as it's running 7. As I mentioned above, restored a snapshot putting dev back to update 4 and now the new certificate is recognized.
 
Hello,

Just trying to get a proper background:

This is a Windows machine?
You place new certs in ProgramData\3CX\Bin\nginx\conf\Instance1 ?
Reload nginx?
Older certs that were in Program Files\3CX Phone System\Bin\nginx\conf\instance1 get copied over and overwrite new certs?
Or older certs in Program Files\3CX Phone System\Bin\nginx\conf\instance1 are the ones being loaded?

Can you check nginx.conf to see where it's looking for certs?

The machine has been doing continues upgrades since before v20, or was it fresh-installed as v20?
 
  • Correct, Windows Server 2016.
  • This server has been running v20 for about 6 months, it was upgraded from v18, and yes it has been patched after upgrading to v20
  • Yes, I placed the new certs in ...ProgramData\3CX\Bin\nginx\conf\Instance1 and restarted the nginx service - I support 18 instances of 3CX so I do this 18 times a year. 17 production systems running update 6 but not update 7 yet, only 1 system (dev box) is running update 7 and this is the problem child.
  • Based on the message in the activity logs, on the dev box, I looked at the file location ...Program Files\3CX Phone System\Bin\nginx\conf\instance1 and this is when I noticed the old certs, the ones I just replaced, and yet when I checked the systems running update 6, this folder was empty. Keep in mind, I restored a snapshot of dev and it is now back at update 4. I checked this folder ...Program Files\3CX Phone System\Bin\nginx\conf\instance1 and it is empty.

As for checking nginx.conf, I restored this system back to where it is running update 4. So it currently shows this:

ssl_certificate "C:/ProgramData/3CX/Bin/nginx/conf/Instance1/domain_cert_3cxdev.acme.com.pem";
ssl_certificate_key "C:/ProgramData/3CX/Bin/nginx/conf/Instance1/domain_key_3cxdev.acme.com.pem";

However, the cert expires later today so what I can do is drop the the old cert files back into the folder listed above, restart nginx, even reboot and verify the expiration date reflects today. I can then install updates 5, 6, and 7 and then try to apply the new cert files again to see if the same behavior happens.
 
Issue Resolved - it appears it was an issue with my browser. I installed updates 5, 6, and 7 Alpha, then placed my new certs in the folders mentioned above, bounced nginx service and it still reflected the old date. Usually, if I fresh my browser it will then reflect the new cert date but for some reason it was not doing this, however, it did for the other 3 sites/certs that I installed at the same time as this one (two days ago). For some reason I had to flush the browsing history, cookies, and other site data, then restarted the browser and it now reflects the correct date. I'm embarrassed :rolleyes:
 
Thanks @Thiek for reverting with the resolution. Nothing to be embarrassed, browsers are weird beasts. What was the browser? Just for knowledge in case this pops up again in the forum to be able to suggest this fix?
 
Issue Resolved - it appears it was an issue with my browser. I installed updates 5, 6, and 7 Alpha, then placed my new certs in the folders mentioned above, bounced nginx service and it still reflected the old date. Usually, if I fresh my browser it will then reflect the new cert date but for some reason it was not doing this, however, it did for the other 3 sites/certs that I installed at the same time as this one (two days ago). For some reason I had to flush the browsing history, cookies, and other site data, then restarted the browser and it now reflects the correct date. I'm embarrassed :rolleyes:
Always clear browser data or use incognito mode to access a site you just changed the SSL for.

Browsers keep cache of this for hours.
 
  • Like
Reactions: KyriacosS_3CX
I'm using the latest version of Chrome. Sort of in my defense, I do this 18 times a year and this was first where Chrome did not reflect the new date when refreshed. Plus, I was baffled when I search the Activity Log and saw a message about SSL that pointed out an issue in the folder ...Program Files\3CX Phone System\Bin\nginx\conf\instance1 (old v18 storage location) and when I looked I spotted the certs I just replaced.
 

Forum statistics

Threads
111,955
Messages
589,926
Members
164,857
Latest member
Luca Christiansen