T21P E2 provisioning

Status
Not open for further replies.

JulienM

Platinum Partner
Advanced Certified
Joined
Jan 4, 2022
Messages
66
Reaction score
32
Hello,
I have a problem provisioning Yealink T21P E2.
Environment: 3CX hosted on MS Azure, version 18.0 U6 (Build 889). The phone is up to date (52.84.0.140).

In order for my phone to provision, I have to disable CA certificate verification in the phone settings. When my phone provisions, this option is automatically reactivated, and I have to deactivate this option again to provision it again.

I had no problem provisioning Yealink T53 or T42S.

My server's certificate is issued by the CA "USERTrust RSA Certification Authority" with an intermediary "Gandi Pro SSL CA 2".
I tried to remove the intermediate certificate and even to install a Let's Encrypt certificate, it does not change anything.

Do you have an idea ?
 
Hi Julien,

The phone manufacturer includes some certificates in the phones. They do not include everything though, so please check their documentation directly to find out what that specific model supports.

As for 3CX, our FQDNs come with a Let's Encrypt certificate generated automatically by the system. All supported phones are able to use that successfully. You can set up a test PBX using a 3CX FQDN is you wish to test that.

If you use a custom FQDN, you will have to manually figure out what certificates to use in accordance with what Yealink also supports. Search for Yealink Built-in Certificate List to confirm.
 
I tried to remove the intermediate certificate and even to install a Let's Encrypt certificate, it does not change anything.
And regarding this, I think maybe it was not configured correctly. I have tested that model and firmware on a 3CX PBX with Let's Encrypt and can confirm that it provisions, and re-provisions correctly. Hope this helps your troubleshooting!
 
Hi @JohnS_3CX
Thanks for your return. I don't have any more T21P E2 on hand to do tests, I should have one soon.

What is weird is that in the Yealink documentation (https://support.yealink.com/en/portal/knowledge/show?id=bab64fcca62fd012b682c533) the authority "USERTrust RSA Certification Authority" is not indicated and yet the provisioning of a T42S and a T53 works without problem. Their documentation may not be up to date though.

For Let's Encrypt, it's actually strange that it doesn't work either. I will test all this when I have phone available, I'll let you know.
 
@JohnS_3CX
I just tested again and it finally works as it should with a Let's Encrypt certificate. The problem is that I had the "DST Root X3" root certificate in my chain. Since it's expired, it didn't work. After deleting it, I manage to provision the T21P E2 without problem. So I'm going to buy a certificate on Godaddy.
Thanks for your help.
 
  • Like
Reactions: JohnS_3CX
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS