TLS Certificate handshake fails after PBX reboot

Colin911

Premier Customer
Joined
Dec 9, 2018
Messages
80
Reaction score
5
Hello,

We have a TLS trunk configured on our PBX that has a registrar that is not publicly resolvable voip.domain.com. The registrar uses a local DNS entry which will resolve to the proxy IP and the outbound proxy hostname is resolvable publicly. The certificate on the proxy is signed by a CA proxy.domain.com.

Whenever our PBX reboots the TLS handshake fails and we have only been able to restore connectivity by updating the registrar with the proxy name then re-entering the correct registrar name needed for registration.

We need assistance understanding why the 3CX is behaving in this way whenever it reboots.

Many thanks!


Log error:
[CM504005]: Registration failed for: Lc:10002(@1111111r[<sip:10002@voip.[DOMAIN].com:5060/TLS>]); Cause: Cause: 503 Certificate Name Mismatch/REGISTER from local



Settings here.

1760110831968.png

1760110885461.png
 
Hello @Colin911 ,

This sounds all verry strange?
Changing a fqdn name in a fully secure TLS connection by means of DNS, uhhhhh
I am out, and so is the connection

Paulo

P.S. If you do get this fully working, please ask the registor to make a entry for secure.yourbank.com to dns happybanking.paulo.com i will do all the transactions amazing secure :)
 
This might help.

  • The PBX will try to match that common name with the provider's “Registrar” value used in the provider's settings.

If during the TLS handshake the provider is advertising the proxy host name as its common name then the TLS handshake will fail.
If they need the registrar name for registration to work ask them to add the registrar name as an alternative name in their certificate.
 

Latest Posts

Forum statistics

Threads
111,990
Messages
590,161
Members
164,926
Latest member
tohoken1