Solved SIP TLS works on one machine, same config fails on another

Status
Not open for further replies.

Hamija

Free User
Joined
Nov 17, 2020
Messages
4
Reaction score
2
Hi,

I got a strange problem with 3CX 16.0.655.

Machine #1: Debian (stretch 9.13) provided by 3cx installed in a VM:
  • configured a SIP trunk
  • uploaded the correct TLS root cert
  • enabled TLS transport
  • trunk connects OK, no problem
Machine #2: Raspberry Pi OS (buster 10) + 3cx install script:
  • configured a SIP trunk
  • uploaded the correct TLS root cert
  • enabled TLS transport
  • [CM504005]: Registration failed for: Lc:10003(@X-Test[<sip:[email protected]-online.de:0/TLS>]); Cause: Cause: 503 Certificate Validation Failure/REGISTER from local
Trunk config and root cert are exactly the same on both machines.

What can I do to debug this? I'm grateful for any suggestions.
 
Allrighty, rubber duck debugging in full effect! :D

From stretch to buster, Debian changed defaults in /etc/ssl/openssl.cnf

stretch behaviour can be replicated in buster by adding
MinProtocol = None
CipherString = DEFAULT


Once I did this, the SIP trunk in question connected instantly using TLS.

I'm aware this is something I should discuss with my provider instead of lowering security requirements but maybe some poor soul finds this post via google some day and can rest in peace.
 
  • Like
Reactions: YiannisH_3CX
Good troubleshooting, but also an example of why TLS isn't available by default really anywhere. I think once TLS actually becomes a requirement for anything then 3CX will probably start working with approved providers to support SIP-TLS using the 3CX FQDNs/LE
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet