SSL failure due to Server 2008 and upgrade issue

Status
Not open for further replies.

numerii

Customer
Basic Certified
Joined
Jun 26, 2009
Messages
30
Reaction score
2
So a couple of my 3CX installations are on Server 2008 which is now unsupported and is causing SSL Certificate errors to happen. I had planned to upgrade to Server 2016 this weekend but when I go to upgrade I'm now getting

Certificate Authority Error: ID (429) - too many certificate requests for the same FQDN. This means you have tried to generate a certificate for this FQDN more than 5 times in the last 7 days. If you want this certificate you need to wait until the counter is adjusted. If you cannot wait, you will need to choose another FQDN. To re-install 3CX using the same license key with a different FQDN you need to release your current FQDN to free your license. Follow this guide: https://www.3cx.com/docs/fqdn-management-allocation/

I have researched this and this seems to be set by LetsEncrypt as mentioned here - https://letsencrypt.org/docs/rate-limits/

It seems I have to either use another FQDN for 3CX which I can't as I have remote extensions which I cannot access over the weekend and these all need to be working on Monday morning.

I have also read that if I uninstall the current 3CX installation to unbind the FQDN I then won't be able to reinstall as the restore process needs the SSL certificate so I'm kind of stuck and looks like I may need to wait until the 'counter is adjusted'

How do I then stop 3CX from continuing to try each day to renew the SSL certificate to allow the counter to come down so I can then upgrade this properly? I'm thinking I may need to postpone this task until next weekend now or is there a way to do this so I can get this done this weekend?
 
Upgrade to 15.5sp6a should help.
 
2008 > backup > restore on 2016 > ssl error?

2008 > upgrade to 2016 > ssl error?

2008 > upgrade to 15.5sp6a > error?
 
I think this thread also explains my issue

https://www.3cx.com/community/threads/7-day-wait-for-fqdn.55452/

I believe 3CX tries each night at around 3am to renew the 3cx.co.uk FQDN - this will fail each time due to the underlying operating system (2008) not accepting the cryptography.

The problem being that every 7 days there will be 7 attempts to renew the SSL certificate thus taking it over the counter limit set by LetsEncrypt. So unless I switch the PBX off for a few days (which I can't do as it's a working phone system) then this counter will never be below the threshold.

I believe that part of the backup/restore process checks the 3cx.co.uk FQDN but I'm not sure what will happen when the SSL certificate fails due to the counter issue? I must keep this FQDN due to the remote extensions so must be able to restore this after moving it to Server 2016.

Will this allow me to restore the system to my current situation with SSL renewal failing but on the newer OS which will then after a couple of days should then successfully renew?

Or is there a way to stop 3CX trying to renew the SSL each night to get this counter down for a future installation date?
 
this is what a renew of a cert looks like:
tcp 0 0 **********:***** 172.65.32.248:443 ESTABLISHED 26304/python2

You could block ports 443 and 80 on outgoing firewall for the 3cx vm.
You could add acme-v02.api.letsencrypt.org 127.0.0.1 to the hosts file of the 3cx vm
 
  • Like
Reactions: CentrexJ
I've tried both of those options over a couple of nights but 3CX still seems to get an unsucessful renewal attempt. Both times the message says

The SSL Certificate renewal for ********.3cx.co.uk failed - Max certificate limit Exceeded the maximum number of certificate requests. Limit to 5 certificates per domain per week. The SSL certificate is no longer valid or will expire. This is a sign of multiple active installations using the same FQDN.

So I think it has managed to contact LetsEncrypt.
 
How do I then stop 3CX from continuing to try each day to renew the SSL certificate to allow the counter to come down so I can then upgrade this properly? I'm thinking I may need to postpone this task until next weekend now or is there a way to do this so I can get this done this weekend?

In the document you linked above, LE states that:

" Renewals are treated specially: they don’t count against your Certificates per Registered Domain limit, but they are subject to a Duplicate Certificate limit of 5 per week. "

" We use a sliding window, so if you issued 25 certificates on Monday and 25 more certificates on Friday, you’ll be able to issue again starting Monday. "


So I think you don't need to do anything else but just wait.
 
Thanks JohnS

So even without being able to renew the SSL Certificate I should be able to do this process?

1 - Backup current PBX (currently running on Server 2008)
2 - Move backup to new Server 2016 installation and restore keeping current 3cx.co.uk FDQN
3 - Await renewal of SSL certificate
4 - Retire old PBX
 
Yes, you don't have any other choice unless the old machine shuts down and stops issuing new requests that fail.
 
Anyone else attempting this after this error - this procedure will not work and you'll be forced to change your FDQN. During the restoration on the new system it will not use your existing FDQN and you will be forced to change it. Not what I had planned but even after releasing the the current 3cx.co.uk FDQN it will not restore and I was forced to change it. This then forced me to go round changing all the remote extensions, not what I wanted on a weekend :(
 
Hi numerii,

Not sure why you released the FQDN?

That is only necessary if your goal is to change your FQDN to a different one.
 
Status
Not open for further replies.

Forum statistics

Threads
111,991
Messages
590,167
Members
164,929
Latest member
Cloudstar