Solved SSL LE certificate renewal fails since 3 days from 2 PBXs

Status
Not open for further replies.

AWS2P

Silver Partner
Basic Certified
Joined
Jan 9, 2014
Messages
5,076
Reaction score
1,096
since following last three days I got a failure on 2 pbxs LE Cert renewal with that kind of message:
The SSL Certificate renewal for fqdn.on3cx.fr failed - Error:
IpUpdater.FqdnGenerationException: Error creating FQDN: Unknown error
at PostInstall.CertificateGenerator.ProcessCertificatesDirectory(String directory, Boolean temporaryCertificateGenerated, Int32 regenerateNotSelfSignedCertificatesFrom, Int32 regenerateNotSelfSignedCertificatesTo, CloudServerStatus statuses, Int32 regenerateCertificateExiredInDays, String appBin, UInt16 sipPort, UInt16 tunnelPort, Nullable`1 httpPort, Nullable`1 httpsPort, Boolean isPassiveFailoverMode, Boolean enableDnsHelper)
at PostInstall.CertificateGenerator.RenewCertificates(String appBin, String nginxConfigFolder, String configurationPath)

A communication error occurred between the DNS Servers and LetsEncrypt. This rarely happens and is usually resolved on the second attempt. 3CX will try again.

Is there 3CX / LE process with known problem running actually? Do I have to worry about something?
 
Last edited:
Hi @aws2p

You should wait until the next day when the PBX will try again and see if the issue persists. Usually when a renewal fails for some reason it will work the next day.

Let me know if you are still having issues.
 
Hi Yiannis,
since a long time we didn't have exchange in forum, my problem here this is the third day with the same error message when trying to renew LE Cert , so i'm not sure at all next day could be better the ones until now.
 
I've open a ticket as French support let me know there's something happening now with LE cert renew.
they ask me to force renew from SSH but I'm asked for a phonesystem password, but I have no idea where to find it
 
1658148778050.png
 
I tried to force as asked by Fr 3CX support but now it's done , I don't know how to check it has really been renewed
1658149087554.png
 
Forced renew seems to have no effect , when I check cert date in browser it's always the last one from 12 of may
1658150814439.png
 
@aws2p check here :

cat /var/lib/3cxpbx/Data/Logs/PbxConfigToolRenewCertificates.log
 
What do i need to search in a text file with so many lines? is there some filter or text argument I need to find?

I found this as failed result:

2022/07/18 16:55:27.946|Dbg|0001| Disconnecting from PhoneSystem
2022/07/18 16:55:27.951|Dbg|0001| Phone System disconnected
2022/07/18 16:55:27.951|Dbg|0001| Finish updating certificates. Updated 0 certificates
 
Last edited:
This night of the 4th day automatic cert renew did the job on the 2 pbxs.

FR 3CX support let me know that it was a problem on 3CX side with Google flair

Problem Fixed, thanks.
 
Last edited:
  • Like
Reactions: YiannisH_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,991
Messages
590,167
Members
164,929
Latest member
Cloudstar