SSL certificate error

Status
Not open for further replies.

john1902

New User
Joined
May 19, 2021
Messages
13
Reaction score
1
I am posting in the wrong section, as this forum can be quite difficult to use for the casual user. I do not want to use my corporate email address which has my correct system listed, as it is not easily possible for me to change my forum name I don't think - well at least I couldn't find it!

My system info:
  • 3CX Version, Enterprise Annual 18 U7 (Build 312)
  • Server OS, Debian
  • Is the 3CX Server Hosted and where? On premises
  • Has the Firewall Checker passed: YES

I am running a 3CX v18 on-premise instance, subscription expiring in April 2024. I am able to login to the management console OK via the internal IP address of the server, and the phone system functions OK (e.g. our IP hones are functioning OK, can make/receive calls). However if I try to access the server webclient or portal via FQDN *.3cx.co.uk/webclient, then I get an error. The error is NET::ERR_CERT_AUTHORITY_INVALID, which indicates an SSL certificate error.

Now I know that 3CX uses LetsEncrypt if I remember rightly, which issues 90 day SSL certificates. And that there is some kind of scheduled task that means it is renewed automatically by the system every 2-3 months. However I have checked my inbox, and I see a notification from 3CX ([email protected]) that the last time the SSL certificate was renewed was 24/12/2022. So that explains why it has now expired. There are no other automated renewal emails, which I normally get approx every 2 months. And there is no error notification email from 3CX, which is why I was unaware of the issue. I still receive 3CX Communications System messages for other items, so notifications work OK, I was just not notified about any SSL renewal errors. The system is on 24-7, so it is not a case that we power it down overnight when the SSL renewal may occur.

Please could you help point me in the right direction about what I may be able to do, to prompt the system to renew the SSL cert?

Firewall checker
  • resolving 'stun-eu.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX PhoneSystem 01 SIP Server... done
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... done
    • starting service... done
  • testing 3CX PhoneSystem Media Server... done
    • stopping service... done
    • testing port 5090... done
    • testing ports [9000..9398]... done
 
I have done some digging, and found that I do have Event ID 10023 dated 3rd May which says that the SSL Certificate has been renewed. However as I mention, I suspect something has gone wrong as there is no email notification for it and there is a cert error when going to the FQDN. I am happy to share the FQDN via private message.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet