Solved SSL Letsencrypt Problem

Status
Not open for further replies.

njullmann

Bronze Partner
Joined
Jun 26, 2019
Messages
2
Reaction score
0
Hi,

the SSL Certificate can't be renewed.
The following error occures: ( tail -f /var/log/nginx/error.log)
2020/04/27 09:28:24 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 09:35:07 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 09:41:11 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 09:44:49 [error] 2364#2364: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 09:53:43 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 10:07:42 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org
2020/04/27 10:19:03 [error] 2365#2365: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org

A manual update is not working.
/usr/lib/3cxpbx/PbxConfigTool -renew-certificates

Any ideas??

thx
 
Can you send me your License Key in a PM? The first 4 digits should be enough.
I can check for you.
 
Hi
i have the same problem on 3CX 16.0.504 version
that run on Win2008 Server

2020/05/25 10:16:34 [error] 2300#2340: OCSP response not successful (6: unauthorized) while requesting certificate status, responder: ocsp.int-x3.letsencrypt.org, peer: 194.230.81.162:80, certificate: "C:\Program Files\3CX Phone System\Bin\nginx/conf/Instance1/xxxxxx.3cx.eu-crt.pem"

for privacy towards the customer I changed the name of the certificate to xxxxx
 
I checked the status of the Let's Encrypt Service here: https://letsencrypt.status.io/

Currently there seems to be some issue:
1590396839394.png

Let's wait until this is fixed and then wait 24 hours. Your system should try again. Your certificate shouldn't expire in this time, generally we try to renew the certificates ahead of time for this exact reason.
 
Hi, thanks for the reply
The problem seems to have started on a date
2020/05/21 06:41:31

and from the logs we can see that he is trying every 5 minutes to get a new certificate.

so I don't have to do anything but wait for them to fix the problem?

Tiziano
 
Hi, thanks for the reply
The problem seems to have started on a date
2020/05/21 06:41:31

and from the logs we can see that he is trying every 5 minutes to get a new certificate.

so I don't have to do anything but wait for them to fix the problem?

Tiziano
Yes, just check when the Lets Encrypt says that their service is 100% running again, then just wait some time.
Also in the meantime, check that your Firewall is not blocking any traffic from or to activation.3cx.com. Also it is advisable to to exclude this host from any DPI function your firewall may have, as we have seen in the past this causing problems both with activation and certificate generation/renewal.
 
Just an FYI, the automatic certificate renewal happens between 00:00 and 07:00 at a random time.
If the server has no internet during that time, or the server is shut down, the certificate cannot renew.
It will of course try again the next day, but you must ensure that it can connect then.
 
  • Like
Reactions: tiziano.arena@owl
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,952
Messages
589,888
Members
164,843
Latest member
sambannoura