- Joined
- Jul 19, 2021
- Messages
- 3
- Reaction score
- 0
I am having difficulty with the SSL Cert renewal with our on-prem system. Our system had been fine renewing consistently for several years now using a 3CX fqdn. But the middle of January we started receiving an email indicating the Cert renewal had failed (FYI, we have been at v18.0.8.939 since September 2023). After reading some of the forum comments, I let it simmer hoping it was possibly a LE issue or that it might renew during the night. As it was reaching 2 weeks out before expiration, I started to follow a couple of the steps I've found throughout the forums. So far, these are the things I've tried:
HTTPS/SSL error - failed to connect to 3CX Activation server. The HTTPS chain is broken or a non trusted certificate was presented.
Possible causes: Ensure that your firewall or proxy is not performing DPI - Deep packet inspection. Disable SSL inspection from the 3CX Server to activate.3cx.com
Ensure that requests are not proxied.
Check that all operating system updates have been applied.
I also have received an email with the following:
The SSL Certificate renewal for XXXXXX.my3cx.us failed - Max certificate limit Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.
I'm not sure how to tell the 3CX system to hold or delay requesting a SSL renew to allow time for a reset.
I'm to the point where I can try to perform a backup without license key and fqdn, provision a new VM, release the current 3CX provided fqdn, and get a new one. Right now, the system is using a temporary self-signed SSL when the restore wasn't able to retrieve/renew the correct one.
- changed the DNS to 8.8.8.8
- perform a clean installing using latest Debian ISO (v18.0.9.20) and restore from full backup
HTTPS/SSL error - failed to connect to 3CX Activation server. The HTTPS chain is broken or a non trusted certificate was presented.
Possible causes: Ensure that your firewall or proxy is not performing DPI - Deep packet inspection. Disable SSL inspection from the 3CX Server to activate.3cx.com
Ensure that requests are not proxied.
Check that all operating system updates have been applied.
I also have received an email with the following:
The SSL Certificate renewal for XXXXXX.my3cx.us failed - Max certificate limit Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.
I'm not sure how to tell the 3CX system to hold or delay requesting a SSL renew to allow time for a reset.
I'm to the point where I can try to perform a backup without license key and fqdn, provision a new VM, release the current 3CX provided fqdn, and get a new one. Right now, the system is using a temporary self-signed SSL when the restore wasn't able to retrieve/renew the correct one.