Solved Unable to enable Secure SIP - empty Certificate and Private Key

Status
Not open for further replies.

gregober1

SOHO User
Joined
Mar 28, 2024
Messages
15
Reaction score
3
I have the latest v.20 of 3CX PBX and I have a problem with empty fields in Advanced >> Secure SIP
Both "Certificate" and "Private key" fields are empty.

I have seen this threads https://www.3cx.com/community/threads/secure-sip.118450/
It gives a clue on how to re-generate the cert by :

  1. modifying the System >> Settings
    1. Add "TEMPORARY_SELF_SIGNED_CERTIFICATE_GENERATED 1"
  2. then issuing "/usr/lib/3cxpbx/PbxConfigTool -renew-certificates" in CLI

I don't seem to be able to add any directive into the System >> Settings
So I am unable to force renew the cert.

Is there any other way in v.20 to handle this and re-generate the cert to enable the secure SIP ?

Thx for your help.
 
Is this a 3CX FQDN?
 
Yes it is a 3cx URL.
 
Disabling this option cannot revert it back.
You can try to copy the certificates content there but the safest way is to re-install.
 
You mean that I have to re-install the whole system because the cert was disabled or wiped ?

This is the most crazy thing I have ever heard.
There must be another solution, we are talking about three hours of work to configure and install the system…

If 3CX is using Let's Encrypt, there must be ways to re-generate the cert or get it back from the Let's Encrypt bots ?
 
@gregober1
Since your SSL is valid until 11 June, can't you access the OS where the Phonesystem is installed (as if your FQDN is
mxxxxx.3cx.fr is running on-premise), so copy those files (public and private keys) to your local PC so you can then paste them into the Admin console of the Phonesystem in the Secure SIP section.
 
To solve the problem with empty fields in Advanced >> Secure SIP in 3CX v.20, create a new self-signed certificate through the 3CX management console in the "Services" -> "SSL Certificates" section. After creating the certificate, assign it in the SIP transport settings for use. This method will allow you to fill in empty fields without using the command line or changing system settings.
 
Create a new self-signed certificate through the 3CX management console in the "Services" -> "SSL Certificates" section
Can you show me a screenshot of this?
 
  • Like
Reactions: Evolute IT
Something else to add here. Why was this option disabled for you?
Did you disable it accidentally or it was disabled?
Ensure that port 5061 is not used by any other service on that OS.
 
I have accidentally disabled the Secure SIP while trying to configure a SIP trunk.
Never thought it would require a re-install to re-enable it…

All ports are properly configured.
We tend to know what we are talking about when we talk about firewall rules >> this is our company.
 
I have accidentally disabled the Secure SIP while trying to configure a SIP trunk.
Never thought it would require a re-install to re-enable it…

All ports are properly configured.
We tend to know what we are talking about when we talk about firewall rules >> this is our company.
Since you disabled the secure sip, the certificate and private key in this section have been wiped and will not repopulate automatically.

You can grab the contents of both the certificate and private key to repopulate this section from the 3cx servers certificate section via SSH.

I suggest you contact your 3cx partner to assist you with this if you work with one, or open a support ticket with 3cx technical support directly if you self-manage the system via the portal.3cx.com support section.
 
Since you disabled the secure sip, the certificate and private key in this section have been wiped and will not repopulate automatically.

You can grab the contents of both the certificate and private key to repopulate this section from the 3cx servers certificate section via SSH.

I suggest you contact your 3cx partner to assist you with this if you work with one, or open a support ticket with 3cx technical support directly if you self-manage the system via the portal.3cx.com support section.
We were 3CX partners and we manage our PBX on our own.

If you give me the path where I can find the certs, I will be very happy to re-populate them in the right place.

I am not 100% sure, but this seems to have effects on other part of the system… see >> https://www.3cx.com/community/threa...ct-with-4-5g-network-v20a.126201/#post-597372
 
In this case, open a support ticket so we can supply this information. We do not like to provide this information publicly as it contains sensitive information, and we tend not to give out internal system locations where sensitive information can be found, like the certificate's private key.
 
Last edited:
Thanks for your help and well understood.
 
Thanks for your help and well understood.

I don't think I am going to pay 75€ to get to know the path of two cert files… Which should have an associated button on the GUI to be re-generated.

This seems like really excessive !

Would you be kind enough to send me the approximate path to look after ?
Or the name of the files…
 
Ok - so this looks like it is solved.
Thanks a lot for your help.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,953
Messages
589,915
Members
164,850
Latest member
masvty