SSL Certificate Manual Update for 3CX FQDNs

Kevin Attard Compagno

Staff member
3CX Support
Joined
Nov 23, 2006
Messages
549
Reaction score
532

Restoring encrypted connectivity after an auto-renewal failure.​

For all 3CX-provided FQDNs, SSL certificates are configured to be automatically updated. This ensures that your 3CX remains secure, auto-renewing well before expiry. However, if for some reason your 3CX system is unable to reach out to trigger and complete the auto...
Continue reading the Original Blog Post.
 
Last edited by a moderator:
Interesting topics, thank you very much :)

One question the TEMPORARY_SELF_SIGNED_CERTIFICATE_GENERATED variable raises here.
Let's assume we have custom domain name.
Can we ask 3CX to use a self-signed certificate, and put 3CX behind a reverse-proxy (which would hold the main certificate) ?
Goal would be to host 3CX behind a WAF, such as HAProxy Enterprise, or whatever, for security reasons.
I see no reasons why it would not work / not be supported.
But we can discuss it :)
Many thanks !
 
I see no reasons why it would not work / not be supported.

The reason why this will not work, is that HAProxy and any other proxy has no idea what it means to handle real time traffic. For static websites this tools work. However, if WebRTC traffic is routed through these proxies, only garbage data is received at the other end.
 
  • Like
Reactions: bitn2
WebRTC flows could have some kind of passthrough rules.
Reverse proxy sanitizing connections to the portal itself.
 
Nearly every customer project
WebRTC via Proxy = Bad audio qualitity
WebRTC rule on devices, to bypass Proxy and make direct connection = Everyone smiles

RTP (VoIP) is always the unicorn, where you never can trust a firewall or proxy manufacturer
 

Latest Posts

Forum statistics

Threads
111,990
Messages
590,164
Members
164,927
Latest member
tohoken1